From 528a4e72af71c7a057f97f3a3d62e644ce5a3cf9 Mon Sep 17 00:00:00 2001 From: theworker02 Date: Tue, 22 Sep 2026 18:01:06 -0400 Subject: [PATCH] Thicken acquisition diligence package and buyer data room. --- ACQUISITION.md | 212 +++++++++++++++-------- README.md | 66 +++---- docs/acquisition/ASSET_INVENTORY.md | 35 ++++ docs/acquisition/BUYER_EVALUATION.md | 66 +++++++ docs/acquisition/DEPENDENCY_INVENTORY.md | 15 ++ docs/acquisition/EXECUTIVE_SUMMARY.md | 60 ++----- docs/acquisition/HANDOFF_CHECKLIST.md | 28 +++ docs/acquisition/IP_PROVENANCE.md | 14 ++ docs/acquisition/README.md | 47 ++--- docs/acquisition/RISK_REGISTER.md | 14 ++ docs/acquisition/TRANSFER_MANIFEST.md | 52 +++--- 11 files changed, 405 insertions(+), 204 deletions(-) create mode 100644 docs/acquisition/ASSET_INVENTORY.md create mode 100644 docs/acquisition/BUYER_EVALUATION.md create mode 100644 docs/acquisition/DEPENDENCY_INVENTORY.md create mode 100644 docs/acquisition/HANDOFF_CHECKLIST.md create mode 100644 docs/acquisition/IP_PROVENANCE.md create mode 100644 docs/acquisition/RISK_REGISTER.md diff --git a/ACQUISITION.md b/ACQUISITION.md index 391d17a..2a90b7f 100644 --- a/ACQUISITION.md +++ b/ACQUISITION.md @@ -1,108 +1,180 @@ -# Acquisition Brief — BotScope +# Acquisition Brief — BotScope -**Date:** 2026-09-21 -**Status:** Briefing document only. **No acquisition has occurred** by virtue of this file. -**No valuation** is stated in this document. +**Date:** 2026-09-22 +**Repository:** https://github.com/theworker02/botscope +**Default branch:** `main` +**Primary language:** Python +**Status:** Diligence briefing only. **No acquisition has occurred** by virtue of this file. +**License:** Proprietary — sale, written commercial license, or completed asset transfer required (see root `LICENSE`). +**Valuation:** Not stated. +**Contact:** GitHub [@theworker02](https://github.com/theworker02) · [thanks.dev/u/gh/theworker02](https://thanks.dev/u/gh/theworker02) -## Problem +> Cloning or forking this repository does **not** grant production, redistribution, SaaS, OEM, or commercial rights. -Operators and researchers lack a transparent, evidence-gated picture of automated Internet traffic versus human-likely traffic. Existing tools often force certainty, conflate a single site’s logs with “the Internet,” or require cloud accounts before a first measurement. +--- -BotScope addresses this with: +## 1. Executive thesis -- An **Internet-wide census surface** (Global Observatory) that federates public crawler/IP panels and optional CDN estimates -- A **local measurement workstation** (CLI + native Qt Observatory) for authorized logs, sessions, and live capture -- An **UNKNOWN-first** classification posture with provenance badges (OBSERVED / CLASSIFIED / INFERRED) +This project is **proprietary**. Production use, redistribution, and commercial deployment require a written commercial license or completed acquisition. See [LICENSE](./LICENSE) and [ACQUISITION.md](./ACQUISITION.md). Contact [@theworker02](https://github.com/theworker02). BotScope **Python-first observability for an Internet-wide census of automated traffic.** -## Product surfaces +**Why a buyer cares:** BotScope packages transferable product IP — source, docs, in-repo brand assets, and a diligence room under `docs/acquisition/` — under a clear proprietary posture so diligence can proceed without mistaking the repo for open source. -| Surface | How to reach it | Notes | -|---------|-----------------|-------| -| CLI | `botscope ` | Headless analyze, hello, doctor, federation, … | -| First-run | `botscope hello` | Offline demo end-to-end; no GUI/network/API keys | -| Ease of access | `botscope access` / `botscope quickstart` | Install paths, data locations, privacy defaults | -| Desktop Observatory | `botscope` or `botscope gui` | Native Qt / PySide6 — not a website | -| Global Observatory | GUI **Global** page / `botscope federation` | Zero-auth public sources; Radar optional | -| Python API | `from botscope import Analyzer` | Same pipeline as CLI | -| PyPI package | `pip install botscope` / `botscope[gui]` | v2.0.0 | +--- -Network contribution stays **OFF by default**. Zero-config for local logs: no account, no cloud profile, no API key. +## 2. Product snapshot -## What is included in a transaction (typical) +| Item | Detail | +|------|--------| +| Product | BotScope | +| Repo | `theworker02/botscope` | +| Language | Python | +| Open source? | **No** — proprietary | +| Rightsholder | theworker02 | +| Diligence pack | `docs/acquisition/` | -- Git repository and original BotScope source/docs (subject to agreement) -- Asserted copyright in original works (subject to counsel / chain of title) -- Branding assets created for BotScope (registration status UNKNOWN) -- Acquisition data room under `docs/acquisition/` +### Capability highlights (from current materials) -## What is NOT included +- Build a **worldwide automation census** in Global Observatory from federated zero-auth public sources (crawler IP ranges, Common Crawl catalog, and similar) plus optional Cloudflare Radar CDN estimates +- Classify requests from combined/common access logs (and optional PCAP / live paths) +- Separate **OBSERVED** totals from **CLASSIFIED** shares, with provenance badges +- Keep an honest **UNKNOWN** outcome instead of forcing certainty +- Explore both **global census views** and local sessions in a **native desktop Observatory** (Qt / PySide6 — not a website) +- **Not** limited to a single site or sensor — Global Observatory is the Internet-wide census surface +- **Not** a claim that one local log alone equals the whole Internet (local shares stay labeled local; the census comes from federated global sources) +- **Not** a cloud SaaS — analysis and preferences stay on your machine by default +- **Not** a substitute for authorization: only analyze systems and traffic you own or have permission to measure +- **Internet-wide census**: Global Observatory is the census product — federated public panels and optional CDN estimates. +- **Local-first**: sessions and preferences stay on disk unless you explicitly enable network contribution. +- **Provenance-aware**: OBSERVED counts are never relabeled as CLASSIFIED shares; local KPIs stay distinct from the global census. -- Historical Apache-2.0 grants already received by third parties -- Operator-published IP range data / Cloudflare Radar data -- Third-party dependency source -- Buyer cloud accounts or secrets -- Fabricated user/revenue/census metrics (none claimed) +--- -## Maturity +## 3. Problem / opportunity -v2.0.0 on PyPI; short git history. Single human maintainer + Dependabot. See `docs/acquisition/EXECUTIVE_SUMMARY.md`. +Teams evaluating BotScope typically need either (a) a commercial right to run or embed it, or (b) outright ownership of the Product IP for strategic build-out. Public GitHub visibility without a proprietary license creates false assumptions about free production use. This brief and the linked data room make the commercial path explicit. -## Technical differentiation +--- -- Evidence-gated classification with UNKNOWN-first posture -- Federated public panels for an Internet-wide census story (local KPIs stay dataset-scoped) -- Offline-first first-run (`botscope hello`) and diagnostics (`botscope doctor`) -- Optional local GUI Observatory and live capture extras +## 4. What ships today -## Transferable IP / third-party / limitations +Honest maturity: treat repository contents, README claims, tests, and release tags as the source of truth. Do not assume production customers, ARR, filed patents, or SLAs unless separately evidenced in diligence. -See: +Typical transferable surfaces: -- `docs/acquisition/IP_AUDIT.md` -- `docs/acquisition/TRANSFER_MANIFEST.md` -- `docs/acquisition/BOTSCOPE_DILIGENCE.md` -- `docs/acquisition/DEPENDENCY_AUDIT.md` +- Source tree and build/test scripts present in-repo +- Documentation and design notes +- Acquisition / diligence markdown under `docs/acquisition/` +- Branding assets committed to the repository (if any) -## Demo path (buyer / evaluator) +--- -Fresh machine, no secrets required for the minimal path: +## 5. Demo / evaluation path (buyer) +Minimal path (no secrets required unless README says otherwise): + +``` ```bash pip install botscope -botscope doctor botscope hello -botscope hello --keep-session demo.bscope -botscope access ``` - -With GUI extras: - ```bash -pip install 'botscope[gui]' +botscope hello --keep-session hello.bscope +botscope hello --json +``` +```bash +botscope access +pip install "botscope[gui]" # if you want the Observatory botscope gui ``` - -From a clone (contributors / diligence): - ```bash -git clone https://github.com/theworker02/botscope.git && cd botscope -python3 -m venv .venv && source .venv/bin/activate -pip install -e '.[dev]' +pip install "botscope[gui]" +``` +```bash +pip install botscope +``` +```bash +git clone https://github.com/theworker02/botscope.git +cd botscope +python -m venv .venv +# Windows: .venv\Scripts\activate +# macOS/Linux: source .venv/bin/activate +pip install -e ".[gui,dev]" +``` +```bash +botscope doctor botscope hello -pytest -q +botscope demo --output demo_analysis.bscope +botscope open demo_analysis.bscope ``` +```bash +botscope gui +# or simply: botscope +``` +```bash +botscope analyze path/to/access.log --output analysis.bscope +botscope report analysis.bscope --format markdown --output report.md +``` + +Extended evaluation: `docs/acquisition/BUYER_EVALUATION.md`. Written NDA / evaluation grants may be required for private materials. + +--- + +## 6. What a transaction typically includes + +Subject to definitive schedules: + +| Included (typical) | Excluded (typical) | +|--------------------|--------------------| +| Repo materials + asserted original IP | Seller personal accounts / unrelated repos | +| Docs + diligence room at closing | Third-party dependency source under separate licenses | +| In-repo brand marks as assigned | Secrets without rotation plan | +| Know-how captured in docs | Fabricated revenue, user, or adoption metrics | + +--- + +## 7. Suggested deal structures + +| Structure | When it fits | +|-----------|--------------| +| Non-exclusive commercial license | Deploy/run under seat or environment terms | +| Exclusive field-of-use license | Buyer wants exclusivity; seller may retain entity | +| Asset / IP assignment | Buyer wants ownership of Materials outright | +| OEM / redistribution | Separate agreement — not implied here | + +Commercial terms (price, earnouts, escrow) are negotiated under NDA with counsel. + +--- + +## 8. Buyer diligence checklist + +- [ ] Confirm Rightsholder identity and authority to sell/license +- [ ] Inventory Materials (`docs/acquisition/ASSET_INVENTORY.md`) +- [ ] Review IP posture (`IP_PROVENANCE.md`) and dependencies (`DEPENDENCY_INVENTORY.md`) +- [ ] Run evaluation script (`BUYER_EVALUATION.md`) +- [ ] Review risks (`RISK_REGISTER.md`) +- [ ] Agree transfer scope (`TRANSFER_MANIFEST.md`) and handoff (`HANDOFF_CHECKLIST.md`) +- [ ] Supersede root `LICENSE` at closing via definitive agreement + +--- + +## 9. Related documents -Expected: commands exit 0; demo output is labeled **DEMO**; no fabricated Internet-wide rates. Detailed script: `docs/acquisition/BUYER_DEMO.md`. First-hour operator guide: `docs/guides/EASE_OF_ACCESS.md`. +| Document | Purpose | +|----------|---------| +| `LICENSE` | Proprietary — no default grant | +| `docs/acquisition/README.md` | Data-room index | +| `docs/acquisition/EXECUTIVE_SUMMARY.md` | One-page thesis | +| `README.md` | Product overview | +| `SECURITY.md` | Vulnerability reporting | +| `COMMERCIAL.md` | Licensing contact path | +| `.github/FUNDING.yml` | Sponsors / thanks.dev | -## Handoff / evaluation +--- -- `docs/acquisition/HANDOFF_PLAN.md` -- `docs/acquisition/BUYER_DEMO.md` -- `docs/acquisition/BUYER_DUE_DILIGENCE_CHECKLIST.md` -- `docs/acquisition/CHANGE_OF_CONTROL_CHECKLIST.md` +## 10. Disclaimer -## Acquisition contact +This package is informational and **does not** create a binding offer, grant of rights, or investment advice. Engage counsel for any transaction. -GitHub [@theworker02](https://github.com/theworker02) · https://github.com/theworker02/botscope +--- -Commercial / license questions: see root `COMMERCIAL.md` and `SUPPORT.md`. +*Document version: 2.0.0 / 2026-09-22 · Classification: acquisition briefing* diff --git a/README.md b/README.md index a17a74f..c3687b5 100644 --- a/README.md +++ b/README.md @@ -12,7 +12,7 @@ This project is **proprietary**. Production use, redistribution, and commercial **Python-first observability for an Internet-wide census of automated traffic.** -BotScope is an **Internet-wide bot traffic census**: the Global Observatory federates public crawler/IP panels, crawl catalogs, and optional CDN estimates into a worldwide automation picture — alongside a local analyzer and native Qt desktop Observatory for authorized logs, sessions, and live capture. +BotScope is an **Internet-wide bot traffic census**: the Global Observatory federates public crawler/IP panels, crawl catalogs, and optional CDN estimates into a worldwide automation picture — alongside a local analyzer and native Qt desktop Observatory for authorized logs, sessions, and live capture. [![CI](https://github.com/theworker02/botscope/actions/workflows/ci.yml/badge.svg)](https://github.com/theworker02/botscope/actions/workflows/ci.yml) [![PyPI](https://img.shields.io/pypi/v/botscope.svg)](https://pypi.org/project/botscope/) @@ -25,7 +25,7 @@ BotScope is an **Internet-wide bot traffic census**: the Global Observatory fede [![Tests](https://img.shields.io/badge/tests-pytest-0A9EDC?logo=pytest&logoColor=white)](https://github.com/theworker02/botscope/actions/workflows/ci.yml) [![Status](https://img.shields.io/badge/status-v2.0.0%20beta-informational)](CHANGELOG.md) -**Install from PyPI:** [`pip install botscope`](https://pypi.org/project/botscope/) · GUI: [`pip install "botscope[gui]"`](https://pypi.org/project/botscope/) +**Install from PyPI:** [`pip install botscope`](https://pypi.org/project/botscope/) · GUI: [`pip install "botscope[gui]"`](https://pypi.org/project/botscope/) > Network contribution is **OFF by default**. BotScope does not perform unauthorized scanning. > Zero-config for your own logs: **no account**, **no cloud profile**, and **no API key** required to classify local traffic. @@ -34,7 +34,7 @@ BotScope is an **Internet-wide bot traffic census**: the Global Observatory fede ## Try in 60 seconds -No GUI, no network, no API keys — just a labeled offline demo: +No GUI, no network, no API keys — just a labeled offline demo: ```bash pip install botscope @@ -66,18 +66,18 @@ First-hour guide: [`docs/guides/EASE_OF_ACCESS.md`](docs/guides/EASE_OF_ACCESS.m Observatory dashboard with DEMO DATA banner, KPIs, composition ring, and Traffic Pulse

-*Observatory — KPI cards, composition ring, Traffic Pulse, and category breakdown on the bundled synthetic demo corpus (DEMO DATA banner visible).* +*Observatory — KPI cards, composition ring, Traffic Pulse, and category breakdown on the bundled synthetic demo corpus (DEMO DATA banner visible).* | | | |:--:|:--:| -| Global Observatory Internet-wide census
*Global — Internet-wide census from zero-auth public sources; Cloudflare Radar optional* | Events table with query filter
*Events — virtualized table, query language, Classification Inspector* | -| Bot Library known vs observed
*Bot Library — known signatures vs observed-in-dataset markers* | Sources registry table
*Sources — registry status for public feeds and optional providers* | +| Global Observatory Internet-wide census
*Global — Internet-wide census from zero-auth public sources; Cloudflare Radar optional* | Events table with query filter
*Events — virtualized table, query language, Classification Inspector* | +| Bot Library known vs observed
*Bot Library — known signatures vs observed-in-dataset markers* | Sources registry table
*Sources — registry status for public feeds and optional providers* |

Settings preferences panel

-*Settings — local theme, privacy, and optional Cloudflare Radar token for CDN estimates (field shown empty; no account required).* +*Settings — local theme, privacy, and optional Cloudflare Radar token for CDN estimates (field shown empty; no account required).* --- @@ -89,9 +89,9 @@ Animated tour of the main Observatory pages (demo data): BotScope GUI tour animated GIF

-[Screenshot strip](docs/assets/demo/botscope-tour-strip.png) · [Recording script / MP4 placeholder](docs/assets/demo/README.md) +[Screenshot strip](docs/assets/demo/botscope-tour-strip.png) · [Recording script / MP4 placeholder](docs/assets/demo/README.md) -To capture a short screen recording yourself (launch → Demo → KPIs → Global → Events), follow the steps in [`docs/assets/demo/README.md`](docs/assets/demo/README.md) and drop `botscope-demo.mp4` (or `.webm`) beside the GIF. +To capture a short screen recording yourself (launch → Demo → KPIs → Global → Events), follow the steps in [`docs/assets/demo/README.md`](docs/assets/demo/README.md) and drop `botscope-demo.mp4` (or `.webm`) beside the GIF. --- @@ -103,16 +103,16 @@ BotScope is an **Internet-wide census of automated traffic**, with a local measu - Classify requests from combined/common access logs (and optional PCAP / live paths) - Separate **OBSERVED** totals from **CLASSIFIED** shares, with provenance badges - Keep an honest **UNKNOWN** outcome instead of forcing certainty -- Explore both **global census views** and local sessions in a **native desktop Observatory** (Qt / PySide6 — not a website) +- Explore both **global census views** and local sessions in a **native desktop Observatory** (Qt / PySide6 — not a website) ## What BotScope is not -- **Not** limited to a single site or sensor — Global Observatory is the Internet-wide census surface +- **Not** limited to a single site or sensor — Global Observatory is the Internet-wide census surface - **Not** a claim that one local log alone equals the whole Internet (local shares stay labeled local; the census comes from federated global sources) -- **Not** a cloud SaaS — analysis and preferences stay on your machine by default +- **Not** a cloud SaaS — analysis and preferences stay on your machine by default - **Not** a substitute for authorization: only analyze systems and traffic you own or have permission to measure -The product’s primary global story is the **Internet-wide census**. Local Observatory KPIs remain dataset-scoped so you can compare your sensors against that census without conflating the two. +The product’s primary global story is the **Internet-wide census**. Local Observatory KPIs remain dataset-scoped so you can compare your sensors against that census without conflating the two. --- @@ -128,7 +128,7 @@ The product’s primary global story is the **Internet-wide censu | **Dataset Health** | Multi-dimension quality scorecard for the loaded session | | **Events** | Virtualized event browser, quick search, shared safe query language | | **Compare** | Session-to-session deltas and classifier-vs-labels panels (no causal claims) | -| **Provenance** | OBSERVED vs CLASSIFIED vs INFERRED — numbers keep their lineage | +| **Provenance** | OBSERVED vs CLASSIFIED vs INFERRED — numbers keep their lineage | | **Exports** | Multi-format reports (Markdown, HTML, JSON, CSV) and research export helpers | | **Live capture** | Authorized log-tail and optional local-interface sniff; measured rates only | | **CLI + Python API** | Headless analyze / query / report / doctor alongside the GUI | @@ -198,7 +198,7 @@ print(result.automation_fraction) print(result.stats.by_category) ``` -More detail: [`docs/guides/EASE_OF_ACCESS.md`](docs/guides/EASE_OF_ACCESS.md) · [`docs/guides/QUICKSTART.md`](docs/guides/QUICKSTART.md) · [`docs/guides/INSTALLATION.md`](docs/guides/INSTALLATION.md) +More detail: [`docs/guides/EASE_OF_ACCESS.md`](docs/guides/EASE_OF_ACCESS.md) · [`docs/guides/QUICKSTART.md`](docs/guides/QUICKSTART.md) · [`docs/guides/INSTALLATION.md`](docs/guides/INSTALLATION.md) --- @@ -233,27 +233,27 @@ Run `botscope --help` or `botscope --help` for options. Tutorials live ``` Access log / PCAP / live sensor - │ - â–¼ + │ + â–¼ Ingest + privacy transforms - │ - â–¼ + │ + â–¼ Classify (rules, identity, optional ML) - │ - ├──► .bscope session store (events, aggregates, workspace) - ├──► CLI reports / export / research packs - └──► Observatory GUI (KPIs, Events, Global census, Live, …) - │ - └──► Global federation → Internet-wide census + │ + ├──► .bscope session store (events, aggregates, workspace) + ├──► CLI reports / export / research packs + └──► Observatory GUI (KPIs, Events, Global census, Live, …) + │ + └──► Global federation → Internet-wide census (zero-auth public sources; Cloudflare Radar if you supply a token) ``` -- **Internet-wide census**: Global Observatory is the census product — federated public panels and optional CDN estimates. +- **Internet-wide census**: Global Observatory is the census product — federated public panels and optional CDN estimates. - **Local-first**: sessions and preferences stay on disk unless you explicitly enable network contribution. - **Provenance-aware**: OBSERVED counts are never relabeled as CLASSIFIED shares; local KPIs stay distinct from the global census. -- Methodology notes: [`docs/research/METHODOLOGY.md`](docs/research/METHODOLOGY.md) · [`docs/research/GLOBAL_ESTIMATION.md`](docs/research/GLOBAL_ESTIMATION.md). +- Methodology notes: [`docs/research/METHODOLOGY.md`](docs/research/METHODOLOGY.md) · [`docs/research/GLOBAL_ESTIMATION.md`](docs/research/GLOBAL_ESTIMATION.md). -Deeper maps: [`docs/architecture/REPOSITORY_MAP.md`](docs/architecture/REPOSITORY_MAP.md) · diagrams in [`docs/architecture/diagrams/`](docs/architecture/diagrams/) · GUI guide [`docs/GUI.md`](docs/GUI.md) +Deeper maps: [`docs/architecture/REPOSITORY_MAP.md`](docs/architecture/REPOSITORY_MAP.md) · diagrams in [`docs/architecture/diagrams/`](docs/architecture/diagrams/) · GUI guide [`docs/GUI.md`](docs/GUI.md) --- @@ -268,7 +268,7 @@ Deeper maps: [`docs/architecture/REPOSITORY_MAP.md`](docs/architecture/REPOSITOR | [`docs/QUERY.md`](docs/QUERY.md) | Safe query language (CLI + GUI + Python) | | [`docs/CAPTURE.md`](docs/CAPTURE.md) | Authorized capture notes | | [`docs/PRIVACY.md`](docs/PRIVACY.md) | Privacy transforms and boundaries | -| [`docs/GLOSSARY.md`](docs/GLOSSARY.md) | Terms (OBSERVED, CLASSIFIED, …) | +| [`docs/GLOSSARY.md`](docs/GLOSSARY.md) | Terms (OBSERVED, CLASSIFIED, …) | | [`docs/research/METHODOLOGY.md`](docs/research/METHODOLOGY.md) | Measurement methodology | | [`docs/research/LIMITATIONS.md`](docs/research/LIMITATIONS.md) | What BotScope will not claim | | [`docs/sources/SOURCE_RESEARCH.md`](docs/sources/SOURCE_RESEARCH.md) | Public source inventory | @@ -304,7 +304,7 @@ Cloudflare Radar is **optional**. Leave Settings blank for normal local-log work 1. Treat **Global Observatory as an Internet-wide census**, built from federated sources with provenance 2. Prefer **UNKNOWN** over forced certainty -3. Separate **OBSERVED** counts from **CLASSIFIED** shares — and local KPIs from the global census +3. Separate **OBSERVED** counts from **CLASSIFIED** shares — and local KPIs from the global census 4. Privacy transforms and local-first storage by default 5. Network contribution remains **OFF** unless explicitly enabled @@ -327,4 +327,8 @@ ruff check src tests scripts ## License -**Source-available proprietary** — evaluation under [LICENSE](./LICENSE); commercial / production use via [COMMERCIAL.md](./COMMERCIAL.md). See [LICENSE_TRANSITION_NOTICE.md](./LICENSE_TRANSITION_NOTICE.md) and [NOTICE](./NOTICE). +**Source-available proprietary** — evaluation under [LICENSE](./LICENSE); commercial / production use via [COMMERCIAL.md](./COMMERCIAL.md). See [LICENSE_TRANSITION_NOTICE.md](./LICENSE_TRANSITION_NOTICE.md) and [NOTICE](./NOTICE). + +## Acquisition diligence + +Buyer-facing diligence materials live in [docs/acquisition/](./docs/acquisition/). Commercial licensing contact path: [COMMERCIAL.md](./COMMERCIAL.md). diff --git a/docs/acquisition/ASSET_INVENTORY.md b/docs/acquisition/ASSET_INVENTORY.md new file mode 100644 index 0000000..6512933 --- /dev/null +++ b/docs/acquisition/ASSET_INVENTORY.md @@ -0,0 +1,35 @@ +# Asset inventory — BotScope + +## Repository surfaces + +| Asset | Location / notes | +|-------|------------------| +| Source tree | Repository root / language packages | +| Tests | `test/`, `tests/`, CI workflows if present | +| Docs | `README.md`, `docs/` | +| Diligence room | `docs/acquisition/` | +| License / notices | `LICENSE`, transition notices if present | +| Funding | `.github/FUNDING.yml` | +| CI | `.github/workflows/` if present | +| Branding | logos/assets folders if present | + +## Capability highlights + +- Build a **worldwide automation census** in Global Observatory from federated zero-auth public sources (crawler IP ranges, Common Crawl catalog, and similar) plus optional Cloudflare Radar CDN estimates +- Classify requests from combined/common access logs (and optional PCAP / live paths) +- Separate **OBSERVED** totals from **CLASSIFIED** shares, with provenance badges +- Keep an honest **UNKNOWN** outcome instead of forcing certainty +- Explore both **global census views** and local sessions in a **native desktop Observatory** (Qt / PySide6 — not a website) +- **Not** limited to a single site or sensor — Global Observatory is the Internet-wide census surface +- **Not** a claim that one local log alone equals the whole Internet (local shares stay labeled local; the census comes from federated global sources) +- **Not** a cloud SaaS — analysis and preferences stay on your machine by default +- **Not** a substitute for authorization: only analyze systems and traffic you own or have permission to measure +- **Internet-wide census**: Global Observatory is the census product — federated public panels and optional CDN estimates. +- **Local-first**: sessions and preferences stay on disk unless you explicitly enable network contribution. +- **Provenance-aware**: OBSERVED counts are never relabeled as CLASSIFIED shares; local KPIs stay distinct from the global census. + +## Usually excluded + +Seller personal accounts, unrelated repos, and unreissued registry tokens — unless listed in the definitive agreement. + +*Updated: 2026-09-22* diff --git a/docs/acquisition/BUYER_EVALUATION.md b/docs/acquisition/BUYER_EVALUATION.md new file mode 100644 index 0000000..d64b270 --- /dev/null +++ b/docs/acquisition/BUYER_EVALUATION.md @@ -0,0 +1,66 @@ +# Buyer evaluation — BotScope + +## Goal + +In 15–45 minutes, verify the Product builds or runs as documented and that proprietary notices are present. + +## Steps + +1. Confirm root `LICENSE` is proprietary and `ACQUISITION.md` exists. +2. Skim `README.md` install/run claims. +3. Execute: + +``` +```bash +pip install botscope +botscope hello +``` +```bash +botscope hello --keep-session hello.bscope +botscope hello --json +``` +```bash +botscope access +pip install "botscope[gui]" # if you want the Observatory +botscope gui +``` +```bash +pip install "botscope[gui]" +``` +```bash +pip install botscope +``` +```bash +git clone https://github.com/theworker02/botscope.git +cd botscope +python -m venv .venv +# Windows: .venv\Scripts\activate +# macOS/Linux: source .venv/bin/activate +pip install -e ".[gui,dev]" +``` +```bash +botscope doctor +botscope hello +botscope demo --output demo_analysis.bscope +botscope open demo_analysis.bscope +``` +```bash +botscope gui +# or simply: botscope +``` +```bash +botscope analyze path/to/access.log --output analysis.bscope +botscope report analysis.bscope --format markdown --output report.md +``` + +4. Run tests if present (`npm test`, `pytest`, `cargo test`, `go test ./...`, etc.). +5. Record README vs observed behavior gaps in workpapers. + +## Pass criteria + +- [ ] Clone succeeds +- [ ] Documented happy path works **or** failure is explained +- [ ] Minimal path needs no surprise secrets +- [ ] License notices intact + +*Updated: 2026-09-22* diff --git a/docs/acquisition/DEPENDENCY_INVENTORY.md b/docs/acquisition/DEPENDENCY_INVENTORY.md new file mode 100644 index 0000000..725962a --- /dev/null +++ b/docs/acquisition/DEPENDENCY_INVENTORY.md @@ -0,0 +1,15 @@ +# Dependency inventory — BotScope + +Inspect manifests present in-repo (`package.json`, `Cargo.toml`, `go.mod`, `pyproject.toml`, `Gemfile`, etc.). + +| Check | Why | +|-------|-----| +| Copyleft depth | Distribution constraints | +| License compatibility | Buyer's intended model | +| Advisories | CVE exposure in locked versions | +| Abandonware | Post-close maintenance | +| Network/telemetry | Privacy / compliance | + +Generate a real SBOM during diligence; this file is a process aid, not a complete SBOM. Ecosystem: **Python**. + +*Updated: 2026-09-22* diff --git a/docs/acquisition/EXECUTIVE_SUMMARY.md b/docs/acquisition/EXECUTIVE_SUMMARY.md index 10be21e..01d65e6 100644 --- a/docs/acquisition/EXECUTIVE_SUMMARY.md +++ b/docs/acquisition/EXECUTIVE_SUMMARY.md @@ -1,51 +1,27 @@ -# Executive Summary — BotScope +# Executive summary — BotScope -**Date:** 2026-09-21 -**Current license:** botscope Source-Available Evaluation License (proprietary source-available) -**Prior license (historical distributions):** Apache License, Version 2.0 (Apache-2.0) -**Transition marker:** 48437fe / merge da22ed8 (2026-09-20) +## One paragraph -## What this is +This project is **proprietary**. Production use, redistribution, and commercial deployment require a written commercial license or completed acquisition. See [LICENSE](./LICENSE) and [ACQUISITION.md](./ACQUISITION.md). Contact [@theworker02](https://github.com/theworker02). BotScope **Python-first observability for an Internet-wide census of automated traffic.** -Internet-wide bot traffic census / local analyzer: federates public crawler IP panels and optional CDN estimates; local log/session analysis and Qt Observatory. +## Strategic read -## Problem addressed +BotScope is proprietary Product IP associated with `theworker02/botscope`. Acquisition value is the working materials, documentation, and a clear path to either a commercial license or an asset purchase — not an open-source community project. -Operators lack a transparent, evidence-gated picture of automation traffic vs human traffic. +## Maturity (honest) -## Maturity +| Claim | Posture | +|-------|---------| +| Production customers / ARR | Not claimed here — verify separately | +| Filed patents | Not claimed — confirm in diligence | +| Completeness vs README | README + tests are authoritative | +| License | Proprietary; sale/license required | -v2.0.0 on PyPI; short git history (≈9 commits). Single human maintainer + Dependabot. +## Buyer next step -## Deployment model +1. NDA if private materials are needed +2. Run `BUYER_EVALUATION.md` +3. Review transfer schedules +4. Term sheet / definitive docs with counsel -pip install; CLI `botscope`; optional GUI; optional Cloudflare Radar token. - -## Language / stack - -Python >=3.10 (Hatchling); optional PySide6 GUI · Version metadata: **2.0.0** - -## Licensing posture (factual) - -- Current tree: proprietary / source-available terms in root `LICENSE` (see exact text). -- Historical distributions under **Apache License, Version 2.0 (Apache-2.0)** remain governed by those terms for copies received, where applicable. -- See [`LICENSE_TRANSITION_ANALYSIS.md`](./LICENSE_TRANSITION_ANALYSIS.md) and root `LICENSE_TRANSITION_NOTICE.md`. - -## Ownership (asserted, not adjudicated) - -Asserted holder: **theworker02 (https://github.com/theworker02)**. -LICENSE: theworker02. Historical Apache: 'BotScope Contributors'. pyproject authors still 'BotScope Contributors'. CITATION.cff previously stale Apache-2.0 (fixed in this program). No CLA/DCO. - -**REQUIRES_LEGAL_REVIEW** before treating ownership as adjudicated or exclusive. - -## What a buyer can expect - -- Ability to evaluate and (after commercial license / acquisition) operate the project with documented handoff materials in this data room. -- Material third-party and historical-license limitations disclosed herein. -- No fabricated users, revenue, benchmarks, or exclusivity claims in this data room. - -## Top diligence risks - -- Operator data redistribution rights for commercial sale -- Apache→proprietary transition -- Dataset fixture license clarity +*Updated: 2026-09-22* diff --git a/docs/acquisition/HANDOFF_CHECKLIST.md b/docs/acquisition/HANDOFF_CHECKLIST.md new file mode 100644 index 0000000..b9f90d7 --- /dev/null +++ b/docs/acquisition/HANDOFF_CHECKLIST.md @@ -0,0 +1,28 @@ +# Handoff checklist — BotScope + +## Before closing + +- [ ] Freeze transfer commit/tag +- [ ] Finalize transfer schedules +- [ ] Inventory secrets to rotate +- [ ] Plan package-registry ownership transfer +- [ ] Plan CI secret migration + +## At closing + +- [ ] Execute definitive agreement +- [ ] Funds / escrow per agreement +- [ ] Transfer repo or deliver archive +- [ ] Re-publish packages under buyer as needed +- [ ] Update public license messaging as agreed + +## After closing (30 days) + +- [ ] Rotate credentials +- [ ] Re-run evaluation on buyer infra +- [ ] Update SECURITY.md contact +- [ ] Archive diligence workpapers + +Seller contact: [@theworker02](https://github.com/theworker02) + +*Updated: 2026-09-22* diff --git a/docs/acquisition/IP_PROVENANCE.md b/docs/acquisition/IP_PROVENANCE.md new file mode 100644 index 0000000..86a6cdb --- /dev/null +++ b/docs/acquisition/IP_PROVENANCE.md @@ -0,0 +1,14 @@ +# IP provenance — BotScope + +| Topic | Statement | +|-------|-----------| +| Rightsholder | theworker02 (https://github.com/theworker02) | +| Product | BotScope | +| Repo | https://github.com/theworker02/botscope | +| Default grant | None — see root `LICENSE` | + +Review git history, contributor agreements, and employer assignment issues in diligence. If `LICENSE_TRANSITION_NOTICE.md` exists, prior OSS grants may survive for historical copies already received; current tree copies are proprietary going forward. Dependencies remain under their own licenses. + +No patent filing is asserted by this document. Trademark registration status is UNKNOWN unless evidenced elsewhere. + +*Updated: 2026-09-22* diff --git a/docs/acquisition/README.md b/docs/acquisition/README.md index dd94de0..39436e6 100644 --- a/docs/acquisition/README.md +++ b/docs/acquisition/README.md @@ -1,40 +1,15 @@ -# Acquisition Data Room — BotScope +# Acquisition data room — BotScope -**Generated:** 2026-09-21 -**Repository:** https://github.com/theworker02/botscope -**Asserted copyright holder (from notices):** theworker02 (https://github.com/theworker02) +**Classification:** Confidential when private materials are shared under NDA. +**Public repo note:** These files are diligence aids; they do **not** grant commercial rights. See root `LICENSE` and `ACQUISITION.md`. -This directory is a **technical and IP diligence data room**. It is factual, -evidence-based, and intentionally discloses defects. It is **not legal advice** -and does **not** assert that an acquisition has occurred. +## How to navigate -## Index +1. `EXECUTIVE_SUMMARY.md` — thesis and maturity honesty +2. `TRANSFER_MANIFEST.md` + `ASSET_INVENTORY.md` — scope +3. `IP_PROVENANCE.md` + `DEPENDENCY_INVENTORY.md` — IP +4. `BUYER_EVALUATION.md` — prove it boots +5. `RISK_REGISTER.md` — known risks +6. `HANDOFF_CHECKLIST.md` — close / transition -| Document | Purpose | -|----------|---------| -| [EXECUTIVE_SUMMARY.md](./EXECUTIVE_SUMMARY.md) | Buyer-facing overview | -| [ASSET_REGISTER.md](./ASSET_REGISTER.md) | What exists in the tree | -| [ARCHITECTURE.md](./ARCHITECTURE.md) | Technical architecture pointer | -| [IP_AUDIT.md](./IP_AUDIT.md) | Ownership / classification | -| [DEPENDENCY_AUDIT.md](./DEPENDENCY_AUDIT.md) | Third-party code deps | -| [THIRD_PARTY_NOTICES.md](./THIRD_PARTY_NOTICES.md) | Attribution obligations | -| [LICENSE_HISTORY.md](./LICENSE_HISTORY.md) | Historical licensing | -| [LICENSE_TRANSITION_ANALYSIS.md](./LICENSE_TRANSITION_ANALYSIS.md) | Relicense analysis | -| [SECURITY_POSTURE.md](./SECURITY_POSTURE.md) | Security diligence | -| [TEST_EVIDENCE.md](./TEST_EVIDENCE.md) | Tests actually run | -| [BUILD_REPRODUCIBILITY.md](./BUILD_REPRODUCIBILITY.md) | Fresh-machine build | -| [KNOWN_LIMITATIONS.md](./KNOWN_LIMITATIONS.md) | Honest limitations | -| [TECHNICAL_DEBT.md](./TECHNICAL_DEBT.md) | Debt register | -| [TRANSFER_PLAN.md](./TRANSFER_PLAN.md) | How to transfer | -| [TRANSFER_MANIFEST.md](./TRANSFER_MANIFEST.md) | Transferability classes | -| [CHANGE_OF_CONTROL_CHECKLIST.md](./CHANGE_OF_CONTROL_CHECKLIST.md) | Dormant post-close checklist | -| [BUYER_DUE_DILIGENCE_CHECKLIST.md](./BUYER_DUE_DILIGENCE_CHECKLIST.md) | Buyer checklist | -| [DISCLOSURE_SCHEDULE.md](./DISCLOSURE_SCHEDULE.md) | Material disclosures | -| [BUYER_DEMO.md](./BUYER_DEMO.md) | Reproducible demo | -| [HANDOFF_PLAN.md](./HANDOFF_PLAN.md) | Day 0 → Day 30 | -| [READINESS_REPORT.md](./READINESS_REPORT.md) | Gate statuses | -| [BOTSCOPE_DILIGENCE.md](./BOTSCOPE_DILIGENCE.md) | Project-specific diligence | - -Root commercial docs: [`COMMERCIAL.md`](../../COMMERCIAL.md) (if present), [`ACQUISITION.md`](../../ACQUISITION.md) (if present), [`LICENSE_TRANSITION_NOTICE.md`](../../LICENSE_TRANSITION_NOTICE.md). - -Legal templates: [`../legal/`](../legal/). +Contact: [@theworker02](https://github.com/theworker02) diff --git a/docs/acquisition/RISK_REGISTER.md b/docs/acquisition/RISK_REGISTER.md new file mode 100644 index 0000000..93953b4 --- /dev/null +++ b/docs/acquisition/RISK_REGISTER.md @@ -0,0 +1,14 @@ +# Risk register — BotScope + +| ID | Risk | L | I | Mitigation | +|----|------|---|---|------------| +| R1 | README overclaims | M | H | Run evaluation; read tests | +| R2 | Third-party license conflict | M | H | SBOM + counsel | +| R3 | Contributor assignment gaps | L | H | History + agreements | +| R4 | Secret leakage in git history | L | H | Scan + rotate | +| R5 | Trademark collision | M | M | Clearance search | +| R6 | Key-person dependency | H | M | Handoff SOW | +| R7 | Cloud/platform dependency | M | M | Architecture review | +| R8 | Prior OSS copies circulating | M | M | Transition notice clarity | + +*Updated: 2026-09-22* diff --git a/docs/acquisition/TRANSFER_MANIFEST.md b/docs/acquisition/TRANSFER_MANIFEST.md index 9177bb0..bbff0cc 100644 --- a/docs/acquisition/TRANSFER_MANIFEST.md +++ b/docs/acquisition/TRANSFER_MANIFEST.md @@ -1,25 +1,27 @@ -# Transfer Manifest — BotScope - -**Date:** 2026-09-21 - -| Asset | Category | Notes | -|-------|----------|-------| -| repository | TRANSFERABLE | github.com/theworker02/botscope | -| source code (original) | TRANSFERABLE | Subject to historical Apache grants | -| PyPI package botscope | TRANSFERABLE_WITH_CONSENT | Trusted Publishing / PyPI ownership transfer | -| datasets/demo + fixtures | TRANSFERABLE | Synthetic/hand-labeled; still confirm intent | -| operator IP list caches | PUBLIC/THIRD-PARTY | Not BotScope-owned; operator terms apply | -| Cloudflare Radar derived metrics | REQUIRES_PERMISSION | API/terms; token is buyer's | -| brand BotScope | TRANSFERABLE_WITH_CONSENT | Registration UNKNOWN | -| secrets | NONTRANSFERABLE | Rotate only | - -## Credentials migration checklist (no secrets committed) - -- [ ] Inventory GitHub secrets / Actions secrets -- [ ] Inventory cloud API tokens (Cloudflare, etc.) -- [ ] Inventory package registry tokens -- [ ] Inventory signing keys -- [ ] Rotate all of the above at closing — **ROTATE_IMMEDIATELY** if any exposure suspected -- [ ] Buyer creates replacement secrets in buyer-controlled accounts - -**NEVER commit credentials.** +# Transfer manifest — BotScope + +## Schedule A — Included (typical) + +1. Git repository `theworker02/botscope` (or content transfer) +2. Original Product source/docs as of closing tag +3. `docs/acquisition/` diligence materials +4. In-repo marks created for BotScope +5. Asserted copyright in original works (counsel to confirm) + +## Schedule B — Excluded (typical) + +1. Seller personal accounts +2. Unrelated theworker02 repositories +3. Personal cloud billing accounts +4. Registry credentials (rotate / re-issue) +5. Historical secrets (rotate) + +## Schedule C — License supersession + +Definitive agreement supersedes root `LICENSE` for the buyer to the extent of conflict. Specify public-repo disposition (archive / private / transfer). + +## Schedule D — Transition assistance (optional) + +Docs-only vs time-boxed engineering help — negotiate separately. + +*Updated: 2026-09-22*