Exit plan
Leaving is easier than joining
A platform that touches your P&L should make exit a trivial operational decision, not a hostage negotiation. This is the standing plan: what you can export, in what format, in what time, and what happens if we cease operations.
Full export
≤ 72 h
Self-serve from /data-export
Open formats
Parquet + JSON
Schemas published on /standards
Read-only window
90 days
Free after termination
Source escrow
Active
Notarised quarterly
What we export, in what time
| Item | Deadline |
|---|---|
| Workspace metadata (users, roles, policies) | Within 24h of request |
| Budgets & budget versions | Within 24h of request |
| Transactions & journal | Within 48h of request |
| Reconciliation rules & runs | Within 48h of request |
| Forecasts (Pacer outputs) | Within 72h of request |
| Audit ledger (Merkle log) | Within 48h of request |
| Signed attestations | Within 24h of request |
If you choose to leave
- Notice of termination triggers an exit-readiness scan with named owner on both sides.
- Full export delivered within deadlines above; read-only access remains for 90 days.
- Sub-processors notified to delete in 30 days; deletion certificates archived in /trust-ledger.
- Final invoice reconciled to journal; outstanding credits paid out per /service-levels.
If we cease operations
- Source-code escrow (Iron Mountain, quarterly notarised deposits) released to customers.
- Continuity vendor on standby to run read-only mode for 12 months post-trigger.
- Open schemas on /standards mean competitors can import customer data without negotiation.
- Trustee-administered wind-down fund covers payout reconciliation and audit handover.