OutProfit Inc., DBA SmartClick AI · Glendale, California
Proposal
Proposal for SVH Tours & Travel Services, Inc.

We propose a security-first audit of the SVH Travel CRM and the 700-site network.

Four areas in seven business days: CRM security and product quality, the WordPress sites, the AI cost of building sites, and how the sites show up in Google and in AI assistants such as ChatGPT. The result is a ranked plan with an effort estimate for every step.

Prepared for
SVH Tours & Travel Services, Inc.
Glendale, California
Prepared by
OutProfit Inc., DBA SmartClick AI
Glendale, California
Document
SVH Technology Audit Proposal
Date
September 24, 2026
CRM firstsecurity first, then product quality
4 areasCRM, WordPress sites, AI cost, visibility in Google and AI assistants
7 daysbusiness days to the written report
Same daya call on anything urgent
1

Basis and scope

Your primary requirement is that the SVH Travel CRM and the site network are secure. Your further objectives are more automation in site creation, with about 2,000 more sites planned, a lower running cost, and faster, better sites. To scope the work you provided the CRM source, a description of the servers behind the 700-plus WordPress sites, your AI billing figures and a site-build log. This proposal is based on that material only, which is covered by the confidentiality terms in section 6.

ProvidedWhat it is
SVH Travel CRMAbout 110,000 lines of Next.js, hosted on Vercel with a Neon Postgres database, Clerk sign-in, card processing through PCIVault and Authorize.Net, email through Resend, SMS through RingCentral, and twelve scheduled jobs. It holds client records, passport scans, saved cards and signed card authorizations, e-signed agreements, every email and SMS thread, and nightly backups.
Site network700-plus WordPress sites on 15 rented servers at Hetzner, ordered recently at Hetzner's current prices. The sites are built as white-label clones of one template, so one shared codebase and plugin stack serve all of them, and they are generated and deployed by an automated pipeline you want to automate further.
AI usageAbout $20,000 spent across two vendors so far, most of it on building the 700 sites. Your build log puts one automated site build at about $23.86 across 525 API calls.

We used this material to size and sequence the audit. This proposal describes the audit; findings come only in the report. It sets out what the audit covers, why each part matters to SVH, and what it delivers. The order of work is the CRM first.

Why the CRM comes first

  • It holds what the business cannot afford to lose. Names, dates of birth, passport numbers and scans, saved cards and signed card authorizations, e-signed agreements, the text of every client email and SMS, and the backups that contain all of it.
  • Everything you plan to build plugs into it. Web leads from the sites, AI assistance for agents, the site pipeline's use of booking facts: each one connects to the CRM. Its security sets the ceiling for everything built on top: a marketing feature connected to the CRM can only be as safe as the CRM's access rules.

You own the report and every recommendation, with no obligation to proceed. Any implementation scope and fee is proposed separately, after you have read the findings. The report is written so that your own team, or any vendor, can act on it.

2

What the audit is worth

The audit delivers two kinds of value.

Protection

The CRM and WordPress security reviews, with recommendations aimed at keeping the same classes of problem from returning.

Scenario savings (gross)

Sized from your own figures at public 2026 prices, on the 2,000 sites you plan to build and the servers that will host them. The AI figures are approximate, based on the spend and build log you provided; the audit replaces them with measured numbers. The figures below are scenarios, not a promise, and they are gross: the audit delivers the report, and implementing its recommendations is separate work with its own cost, by your team or a vendor of your choice. The report turns the scenarios into a ranked plan with an effort estimate for each change.

LeverOn today's footingAfter the recommended changes are implemented
AI cost of building the next 2,000 sites, after the report's AI cost recommendationsabout $48,000 to $57,000
about $24 to $29 per site
about $22,000 to $26,000
about $11 to $13 per site
The same 2,000 builds with the bulk of the AI work on private model hosting (open AI models on dedicated servers, paid by the month instead of per use)about $22,000 to $26,000about $7,000 to $16,000
about $3.50 to $8 per site, plus a flat monthly hosting fee
Server hosting for the sites, today and as the network grows, on fewer servers with Cloudflare's free plan carrying the cached trafficyour current server billup to 50% lower

Gross savings. On the 2,000-site program, about $22,000 to $35,000 from the AI recommendations alone, and about $32,000 to $50,000 with private hosting. On servers, up to 50% of the current bill, at today's size and as the network grows.

All figures in this table and the tiles below are approximate, based on what you shared: about $20,000 of AI spend for 700 sites, one logged build, your current servers, and the 2,000 further sites you plan. The AI rows assume the logged build is typical. The hosting row assumes consolidation behind Cloudflare's free plan can cut the server bill by up to 50%. The tiles count the hosting saving at the full 50% of the server bill you described. The audit measures today's costs and tests the assumptions behind the future ones. Every saving here is gross, before the private hosting fee and the cost of implementing each change; the net saving is what remains after them.

2 to 3xthe audit fee in gross savings, from the AI recommendations on the 2,000-site program and up to 50% of a year's server bill at today's size, before implementation cost
4 to 6xthe audit fee in gross savings, with private hosting and up to 50% of a year's server bill for 2,700 sites, before the private hosting fee, implementation cost and any incident avoided
$11 to $13per site build once the report's AI recommendations are implemented, against about $24 to $29 today

Why the audit comes before the changes. Every step has a way to go wrong that costs more than it saves. A cheaper model can quietly lower page quality, or cost more per page than it appears to; a new feature connected to the CRM inherits every weakness in it; a change to a site's search setup can carry a problem forward instead of leaving it behind; and one bad change rolled across 700 sites becomes 700 problems. The audit puts the steps in the right order with the checks that make each one safe.

3

What we will check, area by area

Each area is reviewed by hand by a senior engineer, with automated tools in support. The report lists what was reviewed in full and what was sampled.

A. The SVH Travel CRM: security and product quality

The primary purpose of the audit: a review of the CRM's source code and configuration, security first, then product quality.

Why it matters to SVH. The CRM runs the agency's daily work and holds its most sensitive data: client and passport details, saved cards, signed agreements and every message. Gaps in software like this do not show in normal use, which is why they are best found in a review.

A1. Security

What we will check

  • Access control, sign-in and sessions
  • Sensitive data and stored documents
  • Card handling, payments and refunds
  • The client portal and links sent to clients
  • Integrations and scheduled jobs
  • Third-party code and configuration

A2. Product quality, errors and reliability

What we will check

  • Errors and reliability
  • Money, dates and core workflows
  • Speed of everyday screens
  • Background jobs and data management
  • Engineering practice
  • Lead handling

B. The WordPress sites: security at scale, hosting and the automation pipeline

The 700-plus sites, the 15 servers that run them, and the pipeline that generates and deploys them, reviewed as one system.

Why it matters to SVH. WordPress is the most used website platform and therefore the most attacked: 11,334 new vulnerabilities in its ecosystem were published in 2025 (Patchstack), most of them in plugins, and heavily targeted ones are exploited at scale within hours. With 700 sites cloned from one template, one vulnerable plugin can compromise hundreds of sites in an afternoon, and the fallout is injected spam, "this site may be hacked" labels in Google and browser warnings on your own brand.

What we will check

  • Security of the shared template, with a spot-check of live sites
  • Cloudflare in front of the sites
  • Servers, capacity and consolidation
  • Backups and recovery
  • Page speed, and how close WordPress can get to Google's "good" speed score
  • Readiness for AI agents that search, compare and book for a visitor
  • The build pipeline and indexing
  • Visitor retention: keeping visitors on the site and bringing them back

C. AI cost of building the sites

The AI cost of the site-building pipeline, from your usage history with both AI vendors and the site-build logs.

Why it matters to SVH. You have spent about $20,000 on AI so far, mostly building the first 700 sites, and you plan about 2,000 more. Without a known cost per site, more automation means more spend at the same rate. The audit measures it, so that the next 2,000 sites are built at a known cost.

What we will check

  • Cost per site build
  • Model choice
  • Cost controls in the pipeline
  • Vendor pricing and volume terms

D. Search visibility: how the sites show up in Google and in AI assistants

A review of the 700-plus sites as one network against Google's current policies, the 2026 enforcement record, and the shift of travel searches into AI answers, with recommendations for the existing WordPress platform. Content quality is checked on a sample of live sites. Some signals cannot change: 700 sites built from one template on shared code will always be recognizable as one operation, and the report says so rather than promising otherwise.

Why it matters to SVH. The network exists to bring leads. Google's spam policies on mass-produced content describe a pattern that large generated networks can match, and 2026 has brought three spam updates and two core updates (Search Engine Journal). Since April 2026, Google's guidance says it may act on the spam reports it receives (Search Engine Land). At the same time, AI answers roughly halve the clicks on the results beneath them (Pew Research Center data), and Google's AI Mode has booked hotels directly since August 2026 (Skift). Knowing which sites produce bookings is what makes every other search decision possible, which is why lead attribution is part of the audit.

D1. Policy exposure and network health

What we will check

  • Exposure under Google's spam policies
  • Indexing and Search Console coverage
  • Content quality
  • Hacked-site risk to search
  • Lead attribution

D2. Visibility in AI assistants such as ChatGPT and Google's AI Mode

What we will check

  • The shift of travel searches into AI answers
  • Citations of your sites in AI answers
  • Page markup that search engines and AI read
4

What you receive

  • The audit report: for each area, the findings in priority order, the recommended change and an effort estimate, with a short summary for the owners at the front.
  • A same-day call on anything we find that should not wait for the report, followed up in writing.
  • A 90-minute walkthrough call on delivery.

What a finding looks like. Every finding carries a title, its severity, what it affects, the evidence, the recommended fix and an effort estimate. Severity has four levels:

  • Urgent: could expose client data or money now; we call you the same day.
  • High: serious, but harder to reach or narrower in effect.
  • Medium: matters in combination with other weaknesses, or affects reliability.
  • Low: good practice and upkeep.
5

What we expect to propose

The report closes with a recommended plan of work, in phases. CRM security always comes before the savings work; what goes into each phase, in what order and when, is set from the findings.

Services we can provide after the report

We can carry out any part of the plan, each scoped and priced from the report, separately and only if you want it. The first step, Protect & Save, covers any time-sensitive CRM fixes and the AI cost program; later work covers CRM hardening and product fixes, private AI hosting, the WordPress sites, search visibility, and ongoing care.

6

Inputs, access and confidentiality

What we need from you at kickoff

  • 30-day usage exports from both AI vendors (by model and API key), the site-build logs with token counts per call and stage, and the number of builds per month.
  • Google Search Console access, or the list of verified properties, Google Analytics access where it exists, and any per-site lead or booking data you hold today.

How we handle access and data

  • All access is read-only, through accounts you own, with multi-factor sign-in.
  • By signing, you authorize the read-only scan of the shared template and a spot-check of live sites. We never run active exploitation against a live system.
  • We do not need card numbers; please do not send them, and any sent by mistake are deleted. We ask for redacted exports wherever possible, limit our access to personal data to what the review requires, and keep only the agreed exports and redacted evidence.
  • Everything you share and everything we find is confidential to SVH, except information that is public or that the law requires us to disclose. Supplied data and evidence are kept for 90 days after delivery, or until a retest you have requested is complete, to answer questions about the report; they are then deleted and we confirm the deletion in writing. We delete them sooner on your written request.
7

Timeline and acceptance

Day 0KickoffSigned proposal and first invoice paid. The seven-business-day clock starts on the day the inputs in section 6 are complete and the access we agree at kickoff is in place. If something is missing we tell you in writing; the clock pauses while any input or access is missing, and delivery moves by the same number of business days.
During the auditUrgent itemsWe call you the same day we find anything that should not wait, then confirm it in writing.
Business day 7Report and walkthroughThe report, with the 90-minute walkthrough at a time agreed with you.
Within 5 business daysAcceptanceTell us in writing within five business days of delivery if anything listed in section 4 is missing; we supply it at no charge. The report is accepted when you confirm or when the five days end. The second invoice is due within 15 days of delivery, as set out in section 8.
8

Fees, payment and credit

Fee schedule

ItemAmount (USD)
SVH Technology AuditCovers all four areas and every deliverable in section 4.$15,000
Total$15,000

Payment schedule

PaymentInvoicedDueAmount (USD)
First installmentOn signingBefore kickoff$7,500
Final installmentOn delivery of the reportWithin 15 days of delivery$7,500

Credit toward Protect & Save

$7,500

With the report, we price Protect & Save (section 5) from its findings. If you go ahead with it within 30 days of receiving that price, and the audit fee has been paid in full, $7,500 is deducted from its first invoice. The audit fee itself is not refunded.

The credit is a deduction on the Protect & Save invoice, never a payout, and is not available on any other service in section 5. The retest below is not credited.

Retest after the fixes

RetestWhat it coversFee
Fixes made by usAfter any engagement in which we did the remediation, we re-verify the fixes we made, once, if requested within 30 days of their completion, and give you a written confirmation of what we verified, for your records.Included
Fixes made by your team or another vendorThe same single re-verification and written confirmation, on fixes we did not make, on the same terms.$3,000

Payment terms

  • Payment in US dollars by wire transfer or check.
  • Bank details are on the invoice; before sending a wire, confirm them with us by phone on a number you have on file for us, as we never change bank details by email.
  • Late payments accrue 1.5% per month.
9

Limitations and next steps

What this audit is not

  • It does not guarantee rankings, traffic or any search outcome; search engines change their rules without notice.
  • It does not guarantee the savings in section 2; they are gross estimates from your figures at public prices, before the cost of implementing the changes, and the report states the assumptions behind each one.
  • It relies on the inputs, access and figures you provide; where these are incomplete or inaccurate, the findings are limited accordingly.
  • It is not legal advice. Where a law is relevant, we flag it and frame the question for your counsel.
  • It is not a PCI, SOC or other compliance attestation, and it does not certify the absence of vulnerabilities. The code review is a reasonable professional effort on the code as of the kickoff date.
  • It does not implement changes. Every recommendation carries an effort estimate so that implementation can be priced separately.

Terms in brief

  • The report and all deliverables are assigned to SVH on full payment. We keep all rights in our pre-existing methods, tools and know-how, and license any part of them in the report to SVH for acting on it. Your team and vendors may use the report; no third party may rely on it without our written consent.
  • To the extent the law allows, our total liability is capped at the fees paid under this proposal, excluding indirect or consequential damages, lost profits and loss of data.
  • Either side may end the engagement by written notice. The first payment is non-refundable; work done beyond it is invoiced in proportion and delivered on payment.
  • Governing law: California; venue: Los Angeles County.
  • Changes to scope are agreed in writing and priced separately before work starts.

What happens after the report

If you decide to act on the findings, we price Protect & Save from the report, and the $7,500 credit applies on the terms in section 8. If you act with your own team or another vendor, the report is built for that too, and the $3,000 retest in section 8 re-verifies their fixes and gives you written results.

To start

  • Sign below and return this proposal.
  • We send the first invoice and a one-page checklist for the inputs in section 6.
  • Kickoff is scheduled the day the checklist is complete.

Signatures

This proposal becomes an agreement when both parties have signed below.

For OutProfit Inc., DBA SmartClick AI Signature Name and title Date
Accepted for SVH Tours & Travel Services, Inc. Signature Name and title Date