Dated source provenance
A source-tree SHA-256 manifest records exactly what existed at generation time. AI can write similar files; it cannot recreate historical provenance after the fact.
The defensible asset is not a claim that code is impossible to reproduce. It is the controlled, dated, signed, buyer-verifiable package: source provenance, VDR materials, deployment evidence, domain presence, transfer guardrails, and founder-specific handover context.
A capable engineer can generate code quickly. A buyer still needs dated evidence, review protocol, transfer perimeter, source integrity, and a coherent acquisition package that survives diligence.
A source-tree SHA-256 manifest records exactly what existed at generation time. AI can write similar files; it cannot recreate historical provenance after the fact.
Public pages expose summaries and hashes, while sensitive implementation details remain NDA-gated until a buyer is commercially qualified.
The package tells a CTO how to verify build, tests, hashes, artifacts, and boundaries instead of asking them to believe marketing language.
The price argument is staged around exclusivity, source review, technical acceptance, commercialization, and revenue milestones.
These endpoints expose hashes, signatures, and evidence boundaries. They deliberately avoid exposing confidential source code in public.
Public API signs the generated source-tree manifest without exposing confidential source files.
Open APIRuntime evidence endpoint signs financial-control metrics and keeps the boundary language visible.
Open evidenceMarkdown documents and provenance manifest bundled for buyer-side review under NDA workflow.
Download ZIPBoundary: this page is acquisition-readiness evidence. It is not a granted patent, independent SOC 2 attestation, bank pilot, legal title opinion, or regulator approval. Those items must be earned through formal external processes.
The public ZIP gives qualified buyers a structured starting point. Full source-code inspection should remain NDA-gated and controlled.
Defines the transfer perimeter: source code, domain, documentation, deployment assets, evidence endpoints, and founder handover.
Classifies confidential know-how and explains the access-control rules that preserve trade-secret value.
Answers the buyer objection that AI tools can recreate code by separating generic code from dated, assembled, validated package value.
Gives qualified buyers a reproducible checklist for build, test, source-provenance, and evidence verification.
Frames a USD 21M-30M headline target through buyer-protective milestones rather than a naive upfront ask.
Budget-aware India filing path for copyright packaging, trade-secret memo, and patent-screening discipline.
For a pre-revenue asset, the credible path is not asking for all cash on day one. The structure protects the buyer while preserving seller upside if the buyer commercializes the asset.
| Component | Indicative Amount | Buyer-Protective Rationale |
|---|---|---|
| Exclusivity deposit | USD 100k-300k | Buyer takes the asset off-market and receives qualified access. |
| Source-review escrow | USD 500k-2M | Paid after verified source review and technical acceptance protocol. |
| Closing payment | USD 2M-5M | Paid on IP assignment, source handover, domain transfer, and transition start. |
| Commercialization milestone | USD 5M-10M | Paid when buyer deploys VaultAI into one or more enterprise customers. |
| Strategic/revenue milestone | USD 10M-15M | Paid when buyer reaches agreed ARR, launch, adoption, or cost-saving thresholds. |
Public proof should create trust. Full code should be released only under a controlled review protocol.