Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .env.example
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
# BotScope environment placeholders — never put real secrets here.
# CLOUDFLARE_API_TOKEN=
# BOTSCOPE_CLOUDFLARE_RADAR_TOKEN=
# BOTSCOPE_RDNS=0
53 changes: 53 additions & 0 deletions ACQUISITION.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,53 @@
# Acquisition Brief — BotScope

**Date:** 2026-09-21
**Status:** Briefing document only. **No acquisition has occurred** by virtue of this file.

## What the project does

Internet-wide bot traffic census / local analyzer: federates public crawler IP panels and optional CDN estimates; local log/session analysis and Qt Observatory.

## Problem

Operators lack a transparent, evidence-gated picture of automation traffic vs human traffic.

## What is included in a transaction (typical)

- Git repository and original BotScope source/docs (subject to agreement)
- Asserted copyright in original works (subject to counsel / chain of title)
- Branding assets created for BotScope (registration status UNKNOWN)
- Acquisition data room under `docs/acquisition/`

## What is NOT included

- Historical Apache-2.0 grants already received by third parties
- Operator-published IP range data / Cloudflare Radar data
- Third-party dependency source
- Buyer cloud accounts or secrets
- Fabricated user/revenue metrics (none claimed)

## Maturity

v2.0.0 on PyPI; short git history (≈9 commits). Single human maintainer + Dependabot.

## Deployment model

pip install; CLI `botscope`; optional GUI; optional Cloudflare Radar token.

## Technical differentiation

Evidence-gated classification with UNKNOWN-first posture; federated public panels; optional local GUI Observatory.

## Transferable IP / third-party / limitations

See `docs/acquisition/IP_AUDIT.md`, `TRANSFER_MANIFEST.md`, `BOTSCOPE_DILIGENCE.md`.

## Handoff / evaluation

See `docs/acquisition/HANDOFF_PLAN.md` and `BUYER_DEMO.md`.

## Acquisition contact

GitHub [@theworker02](https://github.com/theworker02) · https://github.com/theworker02/botscope

No valuation is stated in this document.
2 changes: 1 addition & 1 deletion CITATION.cff
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,6 @@ authors:
- name: "BotScope Contributors"
repository-code: "https://github.com/theworker02/botscope"
url: "https://github.com/theworker02/botscope"
license: Apache-2.0
license: "SEE LICENSE"
version: 2.0.0
# DOI: not assigned — do not invent one
12 changes: 12 additions & 0 deletions docs/DEPLOYMENT.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
# Deployment — BotScope

pip install; CLI `botscope`; optional GUI; optional Cloudflare Radar token.

## Minimal path

See [`acquisition/BUYER_DEMO.md`](./acquisition/BUYER_DEMO.md).

## Rollback

- Application projects: redeploy previous release tag / prior container digest.
- Documentation corpora (ETW): revert git tag; do not delete historical license tags.
5 changes: 5 additions & 0 deletions docs/HANDOFF.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
# Handoff — BotScope

See [`acquisition/HANDOFF_PLAN.md`](./acquisition/HANDOFF_PLAN.md) for Day 0 → Day 30.

Buyer evaluation: [`acquisition/BUYER_DEMO.md`](./acquisition/BUYER_DEMO.md).
15 changes: 15 additions & 0 deletions docs/OPERATIONS.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
# Operations — BotScope

## Health

- Run buyer demo / doctor commands from README where present.
- Monitor CI on GitHub Actions.

## Incidents

- Security: SECURITY.md
- License misuse: docs/legal/RIGHTS_AND_ENFORCEMENT.md (**REQUIRES_LEGAL_REVIEW**)

## Secrets

- Store only in platform secret stores. Rotate on handoff.
22 changes: 22 additions & 0 deletions docs/acquisition/ARCHITECTURE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
# Architecture — BotScope

See also repository root architecture docs where present (`ARCHITECTURE.md`, `docs/`, `README.md`).

## Stack

Python >=3.10 (Hatchling); optional PySide6 GUI

## Deployment

pip install; CLI `botscope`; optional GUI; optional Cloudflare Radar token.

## Summary

Internet-wide bot traffic census / local analyzer: federates public crawler IP panels and optional CDN estimates; local log/session analysis and Qt Observatory.

## Boundaries

- Third-party runtimes, cloud providers, and SDKs are **dependencies**, not owned assets.
- Project-specific diligence: [`BOTSCOPE_DILIGENCE.md`](./BOTSCOPE_DILIGENCE.md).

Buyer should walk architecture with the handoff plan ([HANDOFF_PLAN.md](./HANDOFF_PLAN.md)).
29 changes: 29 additions & 0 deletions docs/acquisition/ASSET_REGISTER.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
# Asset Register — BotScope

**Date:** 2026-09-21

Classification legend: `OWNED` (asserted original work) · `THIRD_PARTY_PERMISSIVE` · `THIRD_PARTY_COPYLEFT` · `PUBLIC_DATA` · `PUBLIC_STANDARD` · `UNKNOWN` · `REQUIRES_PERMISSION` · `REQUIRES_LEGAL_REVIEW`

| Asset | Classification | Notes |
|-------|----------------|-------|
| Git repository | OWNED / REQUIRES_LEGAL_REVIEW | Hosted at https://github.com/theworker02/botscope; copyright chain see IP_AUDIT |
| Original source / docs authored for this project | OWNED / REQUIRES_LEGAL_REVIEW | Subject to contributor/AI issues |
| Root LICENSE / NOTICE | OWNED (text) | Current terms proprietary |
| Historical open-source grants already given | PUBLIC/THIRD-PARTY (grants) | Cannot be clawed back by LICENSE change alone |
| Dependencies | See DEPENDENCY_AUDIT | click, pydantic, rich, platformdirs, packaging; optional PySide6, scapy, numpy/sklearn, duckdb, httpx. No lockfile. No G… |
| Third-party content | See THIRD_PARTY_NOTICES | Public operator IP range JSON (Google, Bing, OpenAI, etc.) under operator terms; optional Cloudflare Radar API; syntheti… |
| Brand / name | UNKNOWN registration | Asserted use by holder; no registration docs in repo |
| Secrets | N/A | Never transferable as committed assets |

## Transfer-oriented inventory

| Asset | Transfer class | Notes |
|-------|----------------|-------|
| repository | TRANSFERABLE | github.com/theworker02/botscope |
| source code (original) | TRANSFERABLE | Subject to historical Apache grants |
| PyPI package botscope | TRANSFERABLE_WITH_CONSENT | Trusted Publishing / PyPI ownership transfer |
| datasets/demo + fixtures | TRANSFERABLE | Synthetic/hand-labeled; still confirm intent |
| operator IP list caches | PUBLIC/THIRD-PARTY | Not BotScope-owned; operator terms apply |
| Cloudflare Radar derived metrics | REQUIRES_PERMISSION | API/terms; token is buyer's |
| brand BotScope | TRANSFERABLE_WITH_CONSENT | Registration UNKNOWN |
| secrets | NONTRANSFERABLE | Rotate only |
46 changes: 46 additions & 0 deletions docs/acquisition/BOTSCOPE_DILIGENCE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,46 @@
# BotScope — Project-Specific Diligence

**Date:** 2026-09-21

## Traffic-data sources

Catalogued in `src/botscope/sources/registry/catalog.py` and `docs/sources/`:
Common Crawl collinfo, Google/Bing/OpenAI/Anthropic/Perplexity/Apple bot IP ranges,
optional Cloudflare Radar, cloud IP ranges, local sensor.

## Source licensing

- Operator-published JSON: review each operator’s terms — **REQUIRES_PERMISSION** / **REQUIRES_LEGAL_REVIEW** for commercial redistribution of cached copies.
- Cloudflare Radar: API token + Cloudflare terms; not transferable as BotScope-owned data.

## API dependencies

- Optional `httpx` network extra; Radar token via env/settings.
- Network contribution off by default per docs.

## Provenance

- Demo logs synthetic (`datasets/demo`).
- Fixtures hand-labeled (`datasets/fixtures`) — not vendor ground truth.

## Bot classification methodology

- Pipeline: ingest → privacy → rules + identity + optional ML → evidence → aggregates.
- UNKNOWN is first-class; ML must not override verified identity.
- Global headline gated on multiple independent traffic-share sources.

## False-positive limitations

- Confidence scores are heuristics, not calibrated prevalence.
- FAQ vs GLOBAL_ESTIMATION messaging conflict noted in audit — treat estimation claims carefully.

## Dataset transferability

- Synthetic/hand-labeled fixtures: likely transferable as original compilation — confirm.
- Operator data: **PUBLIC/THIRD-PARTY** / **REQUIRES_PERMISSION**.
- No MaxMind DB shipped.

## Reproducibility of metrics

- Local demo/doctor path reproducible without tokens.
- Radar-dependent metrics require buyer credentials and are environment-specific.
24 changes: 24 additions & 0 deletions docs/acquisition/BUILD_REPRODUCIBILITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
# Build Reproducibility — BotScope

**Date:** 2026-09-21

## Fresh machine path

```
git clone https://github.com/theworker02/botscope.git && cd botscope
python3 -m venv .venv && source .venv/bin/activate
pip install -e '.[dev]'
botscope doctor
botscope demo
pytest -q
```

## Assumptions

- Stack: Python >=3.10 (Hatchling); optional PySide6 GUI
- No machine-specific absolute paths should be required.
- Cloud credentials are optional unless exercising live provider features.

## Known reproducibility limits

Documented in KNOWN_LIMITATIONS.md and project-specific diligence.
26 changes: 26 additions & 0 deletions docs/acquisition/BUYER_DEMO.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
# Buyer Demo — BotScope

**Target:** fresh machine → clone → install → run → verify (≈10–15 minutes where realistic).

## Exact commands

```bash
git clone https://github.com/theworker02/botscope.git && cd botscope
python3 -m venv .venv && source .venv/bin/activate
pip install -e '.[dev]'
botscope doctor
botscope demo
pytest -q
```

## Expected results

- Commands exit 0 (or documented skip for optional live-cloud steps).
- No secrets required for the minimal path.
- See TEST_EVIDENCE.md for recorded exit codes from this program’s verification runs.

## Out of scope for minimal demo

- Live production cloud credentials
- Shipping malware / real vehicle bus hardware (OpenDashCAN)
- Paid API quotas
13 changes: 13 additions & 0 deletions docs/acquisition/BUYER_DUE_DILIGENCE_CHECKLIST.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
# Buyer Due Diligence Checklist — BotScope

- [ ] Read LICENSE, LICENSE_TRANSITION_NOTICE, NOTICE
- [ ] Read IP_AUDIT + LICENSE_HISTORY + LICENSE_TRANSITION_ANALYSIS
- [ ] Confirm historical Apache License, Version 2.0 (Apache-2.0) exposure acceptable
- [ ] Review DEPENDENCY_AUDIT + regenerate SBOM
- [ ] Review project-specific diligence (BOTSCOPE_DILIGENCE.md)
- [ ] Run BUYER_DEMO.md on a clean machine
- [ ] Review SECURITY_POSTURE + secret rotation plan
- [ ] Review KNOWN_LIMITATIONS + DISCLOSURE_SCHEDULE
- [ ] Counsel review of contributor/AI chain of title — **REQUIRES_LEGAL_REVIEW**
- [ ] Confirm what is excluded (third-party, trademarks, accounts)
- [ ] Validate commercial license pipeline (COMMERCIAL.md)
22 changes: 22 additions & 0 deletions docs/acquisition/CHANGE_OF_CONTROL_CHECKLIST.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
# Change-of-Control Checklist — BotScope

**STATUS: DORMANT.** Do not execute until a transaction actually closes.

- [ ] Execute signed asset/IP agreement
- [ ] Confirm assets actually transferred match the agreement schedule
- [ ] Transfer GitHub repository
- [ ] Transfer domains (if any)
- [ ] Transfer package namespaces where supported
- [ ] Rotate credentials
- [ ] Update copyright notices where appropriate (counsel-directed)
- [ ] Update commercial contact
- [ ] Publish change-of-control notice (from docs/legal template)
- [ ] Update SECURITY.md
- [ ] Update SUPPORT.md
- [ ] Update acquisition status docs
- [ ] Archive superseded commercial documentation
- [ ] Preserve historical license notices / tags
- [ ] Notify commercial licensees where required
- [ ] Migrate infrastructure
- [ ] Verify production operation
- [ ] Produce final transfer receipt
26 changes: 26 additions & 0 deletions docs/acquisition/DEPENDENCY_AUDIT.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
# Dependency Audit — BotScope

**Date:** 2026-09-21

## Summary

click, pydantic, rich, platformdirs, packaging; optional PySide6, scapy, numpy/sklearn, duckdb, httpx. No lockfile. No GPL/AGPL declared in core deps.

## Third-party content (non-package)

Public operator IP range JSON (Google, Bing, OpenAI, etc.) under operator terms; optional Cloudflare Radar API; synthetic demo datasets only.

## Copyleft

No GPL/AGPL/LGPL **declared as core direct dependencies** in the audits performed.
Optional GUI stacks (e.g. PySide6/Qt) may introduce LGPL obligations if redistributed — **REQUIRES_LEGAL_REVIEW** where applicable (OpenDashCAN/BotScope GUI extras).

## SBOM status

Formal CycloneDX/SPDX SBOM may be partial or absent. Buyer should regenerate SBOM at transfer.

## Obligations

- Retain dependency license notices on redistribution.
- Do not relicense third-party code.
- Cloudflare / operator / vendor terms are separate contracts — **REQUIRES_PERMISSION** for some commercial redistributions of derived data.
16 changes: 16 additions & 0 deletions docs/acquisition/DISCLOSURE_SCHEDULE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
# Disclosure Schedule — BotScope

**Date:** 2026-09-21

## Material disclosures

1. **License transition:** Apache License, Version 2.0 (Apache-2.0) → proprietary (48437fe / merge da22ed8 (2026-09-20)). Historical grants remain for historical copies.
2. **Ownership uncertainties:** LICENSE: theworker02. Historical Apache: 'BotScope Contributors'. pyproject authors still 'BotScope Contributors'. CITATION.cff previously stale Apache-2.0 (fixed in this program). No CLA/DCO.
3. **Third-party obligations:** Public operator IP range JSON (Google, Bing, OpenAI, etc.) under operator terms; optional Cloudflare Radar API; synthetic demo datasets only.
4. **Security:** No SECRET_FOUND. Test placeholders for Cloudflare tokens only.
5. **Maturity:** v2.0.0 on PyPI; short git history (≈9 commits). Single human maintainer + Dependabot.
6. **Blockers before diligence:** Operator data redistribution rights for commercial sale; Apache→proprietary transition; Dataset fixture license clarity

## No claims

This schedule does **not** claim revenue, user counts, exclusivity, or completed acquisition.
51 changes: 51 additions & 0 deletions docs/acquisition/EXECUTIVE_SUMMARY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
# Executive Summary — BotScope

**Date:** 2026-09-21
**Current license:** botscope Source-Available Evaluation License (proprietary source-available)
**Prior license (historical distributions):** Apache License, Version 2.0 (Apache-2.0)
**Transition marker:** 48437fe / merge da22ed8 (2026-09-20)

## What this is

Internet-wide bot traffic census / local analyzer: federates public crawler IP panels and optional CDN estimates; local log/session analysis and Qt Observatory.

## Problem addressed

Operators lack a transparent, evidence-gated picture of automation traffic vs human traffic.

## Maturity

v2.0.0 on PyPI; short git history (≈9 commits). Single human maintainer + Dependabot.

## Deployment model

pip install; CLI `botscope`; optional GUI; optional Cloudflare Radar token.

## Language / stack

Python >=3.10 (Hatchling); optional PySide6 GUI · Version metadata: **2.0.0**

## Licensing posture (factual)

- Current tree: proprietary / source-available terms in root `LICENSE` (see exact text).
- Historical distributions under **Apache License, Version 2.0 (Apache-2.0)** remain governed by those terms for copies received, where applicable.
- See [`LICENSE_TRANSITION_ANALYSIS.md`](./LICENSE_TRANSITION_ANALYSIS.md) and root `LICENSE_TRANSITION_NOTICE.md`.

## Ownership (asserted, not adjudicated)

Asserted holder: **theworker02 (https://github.com/theworker02)**.
LICENSE: theworker02. Historical Apache: 'BotScope Contributors'. pyproject authors still 'BotScope Contributors'. CITATION.cff previously stale Apache-2.0 (fixed in this program). No CLA/DCO.

**REQUIRES_LEGAL_REVIEW** before treating ownership as adjudicated or exclusive.

## What a buyer can expect

- Ability to evaluate and (after commercial license / acquisition) operate the project with documented handoff materials in this data room.
- Material third-party and historical-license limitations disclosed herein.
- No fabricated users, revenue, benchmarks, or exclusivity claims in this data room.

## Top diligence risks

- Operator data redistribution rights for commercial sale
- Apache→proprietary transition
- Dataset fixture license clarity
Loading
Loading