Verified Handover Terms
- Version:
- 0.9-beta
- Last updated:
- 2026-10-03
- Effective:
- [set at launch]
Beta (draft) version under legal review before public launch — may change before taking effect. You will be asked to accept again after any material change.
In short
- The service helps the seller and buyer document what is delivered and received, item by item, with digital fingerprints.
- The platform is a neutral technical recorder: not a party to the deal, it holds no funds and guarantees nothing.
- Scans are automated and limited, and are not a security or legal audit.
- The buyer sees the scan report, not the code, before delivery.
- Code archives are deleted automatically 90 days after the deal is completed or cancelled; the certificate and hashes are kept.
1. Scope and Parties
- The service is available between a founder (the seller) and an investor whose intro request for the project was accepted (the buyer).
- These terms should be read with the "Terms of Use" and the "Obligations of the Parties", whose definitions apply.
- The deal itself, including the price and its payment, is a direct agreement between seller and buyer off the platform.
2. Role of the Platform
- The platform is a neutral technical recorder of events and hashes; it is not a party to the deal or an agent of either party.
- The platform does not provide escrow or trust-account services and does not receive, hold or transfer funds.
- The platform does not guarantee code quality, absence of vulnerabilities, valid ownership or the value of the assets.
- The platform takes no commission on the deal. Points may be due only for the optional AI review.
3. Manifest of Items
3.1 Preparing the manifest
- The parties prepare a manifest of items to be delivered. Item types: code repository archive, domain, accounts, data, documents, intellectual property, and other.
- Each item has a clear acceptance criterion.
3.2 Locking the manifest
- Once both parties approve the manifest, it is locked and a SHA-256 fingerprint is computed for it.
- A locked manifest can only be changed by a new approval of both parties, producing a new version and fingerprint.
4. Automated Scanning
4.1 Uploading code
- The seller uploads code archives.
- The seller warrants that it has the right to share and sell the code and that it does not infringe third-party rights.
- The seller grants the Company a limited licence to store and process the code solely for scanning and verification; the licence ends when the archive is deleted.
4.2 Static scans
The platform runs automated static scans (without executing the code) covering:
- Leaked secrets, such as keys and passwords.
- Licences, including copyleft licences.
- Known vulnerabilities in dependencies, using the public OSV database.
- An inventory of code components.
4.3 AI review
- The buyer may request an AI review paid with points, under the "AI Use Policy".
- The review takes place only with the seller's permission.
- The code is never sent to an AI provider. Only the scan report summary and the README file are sent, after the automatic personal-data anonymisation layer described in the "AI Use Policy" has been applied.
4.4 Limits of scanning
- Scans are automated and limited in scope, and are not a comprehensive security, legal or technical audit.
- Scans may miss secrets, licences or vulnerabilities and may produce false results.
- The buyer sees the scan report, not the code, before delivery. Each party is advised to engage independent specialists.
5. Delivery and Verification
- A live checklist shows all manifest items.
- Each item has a status: auto-verified, accepted, or disputed.
- Code delivery is verified by comparing the file-level fingerprints of what was delivered with those of what was inspected.
- Domain transfer is verified via a DNS TXT record.
- Other items are accepted or disputed by the buyer, with a stated reason.
- Automated verification proves only that fingerprints match or that the record exists; it does not prove valid ownership or asset quality.
6. Contracts and Electronic Signature
- Contract templates (asset purchase, share purchase summary, code licence, IP assignment) prepared or reviewed by sponsoring law firms are available.
- Templates are a general starting point. They are not legal advice from the Company; each party is advised to review them with its own lawyer and adapt them. [For review: liability of the Company and sponsoring law firms for templates, and disclosure of sponsor status]
- The parties sign electronically by typing their full name, re-entering their account password and giving explicit consent to the contract text.
- The platform records the signature evidence (typed name, time, IP address) and a hash of the text of each signed document, and keeps them as evidence of the signature.
- The Company adopts this method for signing contracts through the platform; the platform does not use signature certificates issued by an electronic certification service provider.
- Where the law requires a specific form for a particular transaction, such as registering a share transfer with the competent authority or notarising or publicly registering the contract, meeting that form is the parties' own obligation, and they are also free to notarise or formally register any contract in addition to signing it on the platform. The platform does not guarantee that such requirements are met.
7. Handover Certificate
- When items are complete, a handover certificate with a QR code is issued.
- The public verification page shows only the certificate number, dates, hashes and item counts, with no confidential content.
- The certificate is a technical record of what the parties documented on the platform, not a certification by the Company of the validity of the deal or assets.
8. Disputes Between the Parties
- When an item is disputed, the dispute and its reason are recorded in the deal log.
- Resolving the dispute is a matter between the parties. The Company is not an arbitrator, and may provide the stored technical records at the request of both parties or of a competent authority.
- Either party may cancel the deal on the platform as the workflow allows, without affecting its contractual obligations outside the platform.
9. Retention and Deletion
- Uploaded code archives are deleted automatically 90 days after the deal is completed or cancelled.
- Handover certificates, hashes, audit records and signature evidence are retained as evidence. [For review: retention period]
10. Liability
- Each party is responsible for the accuracy of what it provides and decides.
- The Company is not liable for asset defects, undetected vulnerabilities or any party's breach of its obligations, within the limits of the "Terms of Use" and the law.