diff --git a/README.md b/README.md index e9605cd2..022783ec 100644 --- a/README.md +++ b/README.md @@ -73,6 +73,12 @@ Third-party product names and trademarks belong to their respective owners and a SightAdapt does not circumvent DRM or other access controls. Protected content may remain unavailable, blank or unfilterable. Compatibility statements describe observed technical behavior and do not imply partnership, certification or support from a third party. See [the complete third-party names, affiliation and protected-content policy](docs/legal/THIRD-PARTY-NAMES-AFFILIATION-AND-DRM.md). +## Legal release status + +Repository notices, policies, SBOM and package checks are preparation and technical compliance controls; they are not a privileged legal opinion or complete legal clearance. + +The current approved stage is free/open-source alpha development and GitHub distribution. SightAdapt is not approved for production-ready claims, paid licensing, major-store production distribution, enterprise legal warranties/indemnities or complete patent/regulatory-compliance claims until qualified counsel signs off on the exact launch scope and artifact. See [the formal legal review and release gate](docs/legal/LEGAL-RELEASE-GATE.md). + ## Build a standalone EXE The application can be published as a self-contained single-file executable. It does not need to be started with `dotnet run`, and the target computer does not need a separately installed .NET runtime. @@ -115,6 +121,8 @@ Create and validate the final archive according to [the binary packaging standar - [Product identity and brand usage](docs/BRAND.md) - [Intended purpose and medical-device claims policy](docs/legal/INTENDED-PURPOSE-AND-MDR.md) - [Third-party names, affiliation and protected-content policy](docs/legal/THIRD-PARTY-NAMES-AFFILIATION-AND-DRM.md) +- [Formal legal review and release gate](docs/legal/LEGAL-RELEASE-GATE.md) +- [Legal sign-off template](docs/legal/LEGAL-SIGNOFF-TEMPLATE.md) - [Release naming and attribution](docs/RELEASING.md) - [Binary packaging standard](docs/PACKAGING.md) - [Complete functionality](docs/FEATURES.md) diff --git a/docs/README.md b/docs/README.md index bc74e6ce..7a7ed230 100644 --- a/docs/README.md +++ b/docs/README.md @@ -5,6 +5,8 @@ The documentation describes the current SightAdapt implementation and the canoni - [Product identity and brand usage](BRAND.md) — canonical name, `™` notation, descriptions, publisher attribution, intended purpose, third-party compatibility wording, website URL, and asset rules. - [Intended purpose and medical-device claims policy](legal/INTENDED-PURPOSE-AND-MDR.md) — approved general-purpose positioning, prohibited medical claims, terminology, reviewed surfaces and renewed-assessment triggers. - [Third-party names, affiliation and protected-content policy](legal/THIRD-PARTY-NAMES-AFFILIATION-AND-DRM.md) — identification-only mark use, neutral compatibility wording, lack of endorsement, asset restrictions and DRM limitations. +- [Formal legal review and release gate](legal/LEGAL-RELEASE-GATE.md) — responsible publisher, current operating model, counsel package, review topics, public sign-off and invalidation triggers. +- [Legal sign-off template](legal/LEGAL-SIGNOFF-TEMPLATE.md) — non-confidential record for a real professional review decision. - [Patent FTO commercialization gate](legal/PATENT-FTO-GATE.md) — technical feature map, current non-commercial decision, professional-review requirements and re-opening triggers. - [Release naming and attribution](RELEASING.md) — public release-title, tag, artifact, website, publisher, store-claim, compatibility and mark conventions. - [Binary packaging standard](PACKAGING.md) — required legal files, redistribution/affiliation notices, SBOM, exact-version notices, final compliance gate and distribution-format rules. diff --git a/docs/RELEASING.md b/docs/RELEASING.md index df1b2df7..4a7b84df 100644 --- a/docs/RELEASING.md +++ b/docs/RELEASING.md @@ -68,6 +68,14 @@ Include this summary whenever third-party compatibility is discussed: Do not use third-party logos, branded icons, trade dress or promotional assets without permission or another documented lawful basis. Follow [the third-party names, affiliation and protected-content policy](legal/THIRD-PARTY-NAMES-AFFILIATION-AND-DRM.md). +## Formal legal release gate + +Repository notices, SBOMs, policies and CI checks are not a professional legal opinion. Before describing a release as production-ready, selling/licensing it, publishing a production package through a major store, supplying enterprise legal warranties/indemnities or claiming complete legal clearance, follow [the formal legal review and release gate](legal/LEGAL-RELEASE-GATE.md). + +A valid approval requires a dated non-confidential record based on [the legal sign-off template](legal/LEGAL-SIGNOFF-TEMPLATE.md) and tied to the exact artifact checksum, territories, channels, revenue model, customer groups and materials reviewed. Privileged advice remains outside the public repository. + +The current alpha stage has no formal counsel sign-off. Do not use `legally cleared`, `fully compliant`, `non-infringing`, `production approved` or equivalent wording. + ## Required mark notice Include this notice once in the release description or linked legal material: diff --git a/docs/legal/LEGAL-RELEASE-GATE.md b/docs/legal/LEGAL-RELEASE-GATE.md new file mode 100644 index 00000000..b4986564 --- /dev/null +++ b/docs/legal/LEGAL-RELEASE-GATE.md @@ -0,0 +1,168 @@ +# Formal legal review and release gate + +## Current status + +| Field | Current position | +|---|---| +| Status date | 2026-07-29 | +| Responsible publisher/support party | KeyffMS / aiteracja.pl | +| Current approved stage | Free, open-source alpha development and GitHub distribution | +| Production-ready claim | Not approved | +| Paid licensing or sales | Not approved | +| Major-store production distribution | Not approved | +| Enterprise legal warranties/indemnities | Not approved | +| Formal counsel sign-off | Not obtained | + +Repository policies, notices and technical compliance controls are preparation materials. They are not a privileged legal opinion, professional trademark clearance, patent FTO opinion, GDPR assessment or medical-device classification decision. + +SightAdapt must not be described as completely legally cleared, patent-cleared, non-infringing, MDR-compliant or production-approved until qualified professionals complete the reviews applicable to the planned activity. + +## Responsible publisher and support party + +The current public publisher and person/organization responsible for SightAdapt-controlled release and support decisions is: + +**KeyffMS / aiteracja.pl** + +The public contact route is the repository owner and issue tracker at `https://github.com/KeyffMS/SightAdapt`. Sensitive information must use the private-contact procedure in `PRIVACY.md` rather than a public issue. + +Before a commercial launch, counsel must confirm whether a separate legal entity, registered business identity, address, tax status, consumer-contract party or dedicated support contact is required for the planned territories and channels. + +## Current operating model + +| Dimension | Current alpha position | +|---|---| +| Territories | Public internet availability through GitHub; no territory-specific commercial launch approved | +| Distribution channels | Source repository and verified GitHub alpha artifacts | +| Revenue model | Free/open-source; no approved paid license, subscription, sale or advertising model | +| Customer/user types | Individual users, developers and evaluators; no approved enterprise, healthcare or regulated-customer offer | +| Support model | Best-effort repository support; no SLA or paid support obligation | +| Store distribution | No approved production listing in a major store | +| Warranties | Repository MIT warranty disclaimer and separate third-party/Microsoft terms; no commercial warranty | + +Counsel sign-off must define the exact launch territories, channels, commercial model, contracting party, customer groups and support obligations. A sign-off for one scope does not automatically cover another. + +## Counsel review package + +Provide counsel with immutable or versioned copies of the exact materials for the proposed launch: + +### Product and release bytes + +- exact final binary artifact and installer/store container, if applicable; +- archive/container SHA-256 and retained compliance report; +- source commit, release tag, product version, SDK/runtime/RID and publish mode; +- `SBOM.spdx.json`, `LICENSE-REPORT.json` and `DEPENDENCIES.md`; +- `LICENSE.txt`, exact `THIRD-PARTY-NOTICES.txt`, `DOTNET-LICENSE-NOTICE.txt`, `DOTNET-NOTICE-METADATA.json` and `MICROSOFT-DOTNET-REDISTRIBUTION.txt`; +- `THIRD-PARTY-NAMES-AND-DRM-NOTICE.txt` and `PRIVACY.md`. + +### Governance and provenance + +- `DCO.md`, `CONTRIBUTING.md`, pull-request template and DCO workflow; +- contribution provenance/history review and exception register; +- relevant permissions or provenance evidence stored privately; +- security policy and current support-data process. + +### Brand, claims and marketing + +- current README, website pages, metadata and screenshots; +- release notes, store listing, directory text, advertising/social materials and support descriptions; +- `docs/BRAND.md` and preliminary trademark-clearance record; +- intended-purpose/MDR policy and any proposed condition-specific or clinical wording; +- third-party compatibility, affiliation and DRM policy. + +### Commercial and contractual scope + +- planned legal entity/contracting party; +- territories, channels, price/revenue model and taxes; +- customer groups and enterprise/consumer status; +- proposed EULA, terms of sale/use, support/SLA, refund and warranty language; +- requested indemnities, non-infringement statements or insurance requirements; +- data processors/services, hosting, telemetry or support vendors. + +## Required review topics + +Qualified counsel must determine or confirm, for the exact planned launch: + +1. whether the Microsoft .NET redistribution analysis and package implementation are acceptable; +2. whether third-party dependencies, notices, SBOM and license policy are adequate; +3. whether the SightAdapt name/logo trademark decision is adequate for the territories/channels, and whether professional clearance or registration is required; +4. whether the current general-purpose intended-purpose/MDR position remains correct for the product and marketing; +5. whether a patent FTO opinion is required and whether the patent gate has been satisfied; +6. whether contributor provenance/DCO and existing history are adequate; +7. whether privacy, support-data handling, retention and external services satisfy the intended operating model; +8. whether end-user warranty, liability, support, consumer, export and third-party language is appropriate; +9. whether store, accessibility, advertising, product-safety or other regulatory obligations apply; +10. which unresolved risks may be accepted, which require conditions and which block release. + +Different specialists may be required for trademark, patent, privacy/data protection or medical-device questions. A general review must not be represented as covering a specialty it expressly excludes. + +## Current public issue treatment + +| Area | Repository preparation | Professional status | +|---|---|---| +| .NET redistribution | Exact-version notices, redistribution analysis and package notice implemented | Counsel confirmation required before production/paid release | +| Dependency licensing | SPDX SBOM, policy report, notices and final package gate implemented | Ambiguous/custom terms require professional judgment | +| Trademark | Preliminary public-source knockout record completed | Professional clearance optional for current stage; required as counsel determines before major commercialization/registration | +| Intended purpose/MDR | General-purpose non-medical positioning documented | Qualified assessment required before medical targeting/claims | +| Patents/FTO | Technical map and commercialization gate documented | No FTO opinion; mandatory before activities defined by the patent gate | +| Privacy | Local-processing/support-data policy documented | Counsel/DPO review required for intended commercial model, territories and new data flows | +| Contributions | DCO and provenance process implemented | Counsel may require additional historical evidence or CLA for a future model | +| End-user terms | Package notices and MIT disclaimer exist | Commercial EULA/consumer/support/warranty terms not approved | + +## Privileged advice and evidence + +Do not commit privileged legal advice, claim charts, attorney communications, confidential licenses, personal identity documents, contracts or sensitive permission records to the public repository. + +The responsible publisher must maintain a private review file containing: + +- engagement scope and counsel identity; +- exact materials supplied; +- privileged advice and working papers; +- supporting permissions/contracts; +- accepted-risk approvals; +- evidence that release conditions were satisfied. + +The public repository contains only the minimum non-confidential decision record. + +## Public sign-off record + +After counsel review, copy `LEGAL-SIGNOFF-TEMPLATE.md` to a dated file such as: + +```text +docs/legal/LEGAL-SIGNOFF--.md +``` + +The public record must contain: + +- reviewer role/qualification, without disclosing privileged communications; +- review date; +- exact product version, commit, tag and artifact checksum; +- territories, channels, revenue model and customer types covered; +- materials and specialist areas reviewed; +- final decision: approved, approved with conditions, redesign/review required or not approved; +- mandatory pre-release conditions and unresolved non-confidential risks; +- expiration/re-review date and invalidation triggers. + +Do not mark a release approved until every mandatory condition is evidenced privately and reflected in the public status. + +## Invalidation and renewed-review triggers + +A sign-off is invalidated or requires confirmation when any material part of its scope changes, including: + +- product version or final artifact after the reviewed checksum; +- legal entity, publisher, support provider or contracting party; +- territory, store/channel, revenue model or customer group; +- EULA, warranty, liability, support, refund or indemnity terms; +- product name, logo or significant marketing/compatibility claim; +- medical/intended-purpose positioning or condition-specific feature; +- rendering, capture, automation or platform mechanism relevant to patent analysis; +- dependency, runtime, license, notice or SBOM composition; +- telemetry, update checks, cloud service, account, upload or support-data flow; +- contribution/provenance model; +- applicable law, regulator/store rule, claim/assertion or third-party objection; +- counsel's stated expiration or limited scope. + +Minor changes may be covered only when counsel's written scope expressly permits them. + +## Release decision + +Current free/open-source alpha work may continue under the documented limitations. Production-ready claims, paid distribution, commercial licensing, major-store production publication, enterprise warranties/indemnities and complete legal-clearance claims remain blocked until a valid professional sign-off record exists for the exact launch. diff --git a/docs/legal/LEGAL-SIGNOFF-TEMPLATE.md b/docs/legal/LEGAL-SIGNOFF-TEMPLATE.md new file mode 100644 index 00000000..89ee654d --- /dev/null +++ b/docs/legal/LEGAL-SIGNOFF-TEMPLATE.md @@ -0,0 +1,121 @@ +# SightAdapt legal release sign-off — + +> Replace every placeholder before committing this record. Do not use this template as evidence of approval. + +## Decision summary + +| Field | Value | +|---|---| +| Decision | `` | +| Review date | `` | +| Reviewer role and qualification | `` | +| Responsible publisher/contracting party | `` | +| Product version | `` | +| Source commit/tag | `` | +| Final artifact name | `` | +| Final artifact SHA-256 | `<64-character hash>` | +| Compliance report | `` | +| Review expiration/review-by date | `` | + +This public record summarizes a professional review decision without publishing privileged legal advice. It must not expand the scope of the underlying written engagement or opinion. + +## Scope covered + +### Territories + +`` + +### Distribution channels + +`` + +### Revenue and contracting model + +`` + +### Customer or user types + +`` + +### Product and feature scope + +`` + +## Materials reviewed + +- [ ] Exact final artifact and checksum +- [ ] Source commit/tag and release metadata +- [ ] SPDX SBOM, dependency summary and license report +- [ ] SightAdapt license and third-party notices +- [ ] Microsoft .NET redistribution analysis, exact notices and package metadata +- [ ] Third-party names, affiliation and DRM notice +- [ ] Privacy/support-data policy and intended data flows/providers +- [ ] DCO, contribution provenance and exception records +- [ ] Trademark-clearance record, name/logo and brand materials +- [ ] Intended-purpose/MDR policy and all product claims +- [ ] Patent FTO gate and any applicable professional opinion +- [ ] README, website, screenshots, release/store/advertising/support materials +- [ ] EULA/terms, warranty, liability, support, refund and indemnity language +- [ ] Installer/store package and final compliance report + +Additional or excluded materials: + +`` + +## Specialist review areas + +| Area | Reviewer/coverage | Outcome or limitation | +|---|---|---| +| Open-source/dependency licensing | `` | `` | +| Microsoft redistribution | `` | `` | +| Trademark/name/logo | `` | `` | +| Privacy/data protection | `` | `` | +| Intended purpose/MDR | `` | `` | +| Patent/FTO | `` | `` | +| Consumer/commercial terms | `` | `` | +| Other | `` | `` | + +An area not reviewed must be marked `not covered`; it must not be inferred from another area's approval. + +## Mandatory conditions before release + +1. `` +2. `` + +State `None` only when the underlying professional decision expressly has no pre-release conditions. + +## Unresolved and accepted risks + +| Risk | Treatment | Decision owner | Re-review trigger | +|---|---|---|---| +| `` | `` | `` | `` | + +Do not publish privileged reasoning. Record enough non-confidential information to prevent the release scope from being misunderstood. + +## Final public decision + +`` + +## Invalidation triggers + +This sign-off becomes invalid or requires written confirmation when: + +- the final artifact differs from the recorded checksum; +- territories, channels, revenue model, customer types or contracting party change; +- marketing, intended purpose, medical claims or third-party compatibility claims materially change; +- dependencies, runtime, licenses, notices, SBOM or packaging change; +- privacy/data flows, external services or support-data handling change; +- relevant rendering/capture/automation mechanisms change; +- warranty, liability, support or indemnity terms change; +- a regulator/store rule, legal claim, assertion or third-party objection changes the risk; +- the review reaches its stated expiration date. + +Additional scope-specific triggers: + +`` + +## Private review file + +Privileged advice and supporting evidence are stored outside the public repository by: + +``