Skip to main content

Exit and portability

How your data and your evidence leave.

A product whose value is a reconstructible evidence chain has to say how that chain leaves with you. Most vendors answer this question in a negotiation. Answering it here costs us nothing we should be protecting, and it is the question that stalls enterprise agreements at legal.

The short version

Your systems of record are never touched, so there is nothing to unwind in them. EOS holds a canonical copy of what it read, plus everything it derived: reconciliations, evidence packs, decisions, authorities, outcomes. All of it exports in open formats, on request, at any time, at no charge, and the exported evidence still verifies after EOS is gone.

What EOS holds about you

ClassWhat it isExport formatVerifies offline after export?
Source recordsThe canonical copy of what was read from your systems, with source, timestamp and record referenceJSON Lines, CSVYes, against your own systems
Canonical objectsThe reconciled object with every contributing source retainedJSON LinesYes
ReconciliationsEvery detected disagreement, the rule applied, and the sources retained on both sidesJSON LinesYes
Evidence packsThe trace behind a material figure: claim, source, timestamp, transformation, rule, calculationJSON + PDFYes, content-hashed
Decision ledgerEvery recorded decision, the authority that made it, the alternatives considered, the timestampJSON Lines, append-only chainYes, chain verifiable
OutcomesWhat was expected, what was measured, the gap, and whenJSON Lines, CSVYes
Policy and configurationRules, authority graph, field maps, connector configurationJSON, YAMLYes
Audit logAppend-only record of every sync, read, decision and administrative actionJSON LinesYes, chain verifiable

The part that matters

The test we hold ourselves to

An exported evidence pack must still verify on a machine that has never heard of AssetShop, with no account, no network and no vendor in the loop. The verification harness ships inside the export. If an evidence pack only verifies while you are a customer, it was never evidence. It was a subscription.

Timeline and cost

TriggerTimelineCost
Self-service export, any timeImmediate, from the consoleNone
Full estate export on requestWithin 5 business daysNone
Termination, for any reasonExport available for 90 days after the end dateNone
Deletion certificateWithin 30 days of your written instructionNone
Vendor failure or insolvencySee source escrow [not claimed] belowPer escrow agreement

What happens if we are not here

Two mechanisms, at two different maturities, and the difference is stated rather than blurred.

Evidence survives us today Sealed
Exported evidence packs and the decision ledger verify offline with the harness that ships alongside them. This works now, requires nothing from us, and is the mechanism we would rather you rely on.Reproduce: run the harness against any exported pack on a disconnected machine
Source escrow In the register
A conventional software escrow arrangement releasing source and build instructions on defined trigger events. Specified, not established. It becomes an executed instrument at first enterprise signature, and until then this page says so.Status source: READINESS_SCORECARD.md

What we do not do

We do not hold your data hostage behind a proprietary format, charge an exit fee, require notice to export, degrade the export relative to the live product, or retain anything after a deletion instruction beyond what law requires. None of that is generosity. An evidence product that made leaving expensive would be arguing against its own thesis.

Trust centre · Data processing addendum · Verify an evidence pack yourself