
Prima Evidence - Source Code
Sold once. One buyer acquires the complete IP outright — every line of source, every test, every audit artefact — and it is then denied to every other party. No licence, no recurring, no second buyer.
Acquire — begin due diligence →Technical Ledger
| SKU | VLA-GEN-PRI-V1.0 |
|---|---|
| Vendor | Vlaander LTD |
| Classification | Engineering Asset |
| Variant | Default Title |
| Availability | ProvisionedPASSING |
Provenance & integrity.
| Language | TypeScript · React 18 |
|---|---|
| Build | Vite · Wrangler · Node 20+ |
| Edge runtime | Cloudflare Workers · KV · Durable Objects |
| Security | scrypt · JWT (jose) · Zod validation · rate-limitedPASSING |
| Tests | unit · end-to-end · strict tscPASSING |
| Integrity | client-side hashing · Arweave permanence |
| Signing scheme | ed25519 signed releases |
| Signing key | Publishing 2026-Q3 |
| SHA-256 | Publishing 2026-Q3 |
| Release | Publishing 2026-Q3 |
| External audit | Publishing 2026-Q3 |
Value, in your metrics.
| Metric you track | Magnitude |
|---|---|
| Proof permanence | Records are written immutably to Arweave; files are hashed client-side and never leave the browser. |
| Time-to-launch | A complete, deployable proof-of-authorship product — backend, frontend, payments, admin — not a from-scratch build. |
| Operating cost | Edge-deployed on Cloudflare Workers — no servers to run, global low-latency by default. |
| Verification | Any document hash verifies against its on-chain proof through a single public endpoint. |
Build-vs-buy basis.
Reproducing this in-house: approximately 2–4 engineer-months for a senior team familiar with edge-deployed TypeScript web applications, Cloudflare Workers, and Arweave integration. At a loaded cost of $25,000 per engineer-month, that is $50,000–$100,000, or $120,000 after a 20% risk premium for scope overrun. Purchasing the source: $35,000 plus approximately 1 weeks of integration effort. Stated biases: we compare against the high end of the build estimate, apply a 20% risk premium for scope overrun, and exclude opportunity cost. Editable assumptions: engineer-months (2–4), loaded cost per month ($25,000), risk premium (20%). Flip any of these and the comparison adjusts accordingly — the model is yours to defend, not ours to dictate.
Risk allocation.
| Risk | Borne by | Basis | Buyer’s recourse |
|---|---|---|---|
| IP cleanliness | Vlaander LTD | Source warranted as original work, clean of third-party IP at point of sale. | Indemnification capped at the purchase price paid. |
| Benchmark performance | Vlaander LTD | Published numbers must reproduce on the documented hardware. 30-day inspection window from delivery. | Refund of the purchase price within the inspection window. |
| Integration into buyer’s stack | Buyer | Integration footprint published on every product page. No warranty extends to bespoke environments outside the documented targets. | Use the published footprint as the integration spec; engage Vlaander engineering at sales@vlaander.com for paid support. |
| Regulatory compliance in buyer’s jurisdiction | Buyer | Export classified EAR99. Buyer self-screens against restricted jurisdictions and parties under their own legal counsel. | Request a pre-sale export review at sales@vlaander.com — provided at no charge. |
| Vendor continuity | Buyer | No vendor can warrant its own continuation. Source delivered without licence server, kill-switch, or expiry — risk transferred to buyer by the outright-sale model. | Self-maintain in perpetuity using the delivered source; fork freely under the Sale terms. |
| Source-code escrow | Joint | Source is delivered to the buyer at sale, so escrow is structurally unnecessary. Available on request when buyer counsel mandates a third-party deposit. | Request escrow at sales@vlaander.com — buyer-funded; Vlaander participates without charge. |
| Security disclosure post-sale | Joint | Vlaander acknowledges security reports within 24 hours and honours coordinated disclosure indefinitely on shipped versions. Buyer applies remediation in their environment. | Report to sales@vlaander.com — disclosure policy published at /security. |
Scope & maturity.
- The full stack: a Cloudflare Workers backend (Hono, KV, Durable Objects, JWT, Arweave) and a React 18 + TypeScript frontend with user dashboard and admin panel.
- Payment processing, email notifications, API rate limiting, and CI/CD workflows.
- Security posture: client-side hashing, scrypt password hashing, JWT auth, Zod validation, and secure headers.
- A focused single-product application — proof-of-authorship on Arweave — not a general document-management platform.
- Delivered as source to own and operate; live operation, scaling, and any regulatory posture are the acquirer’s.
System Abstract
A blockchain-based proof-of-authorship platform that creates permanent, tamper-proof records of digital documents on the Arweave blockchain. Files are hashed client-side and never leave the browser; the resulting proof is written immutably on-chain, with a single endpoint to verify any hash against it later.
Delivered as a complete, deployable source codebase: a Cloudflare Workers edge backend (Hono, KV, Durable Objects, JWT auth, Arweave integration, payment processing) and a React 18 + TypeScript frontend with a user dashboard and admin panel. Authentication uses scrypt password hashing and JWT; every endpoint is rate-limited and input-validated; the full stack deploys to Cloudflare's edge for global low-latency.
This is the proof-of-authorship product as source you own and operate under your own brand — backend, frontend, payment and email integration, API documentation, and CI/CD workflows — sold outright as proprietary source.
