Exit plan

Leaving is easier than joining

A platform that touches your P&L should make exit a trivial operational decision, not a hostage negotiation. This is the standing plan: what you can export, in what format, in what time, and what happens if we cease operations.

Full export

≤ 72 h

Self-serve from /data-export

Open formats

Parquet + JSON

Schemas published on /standards

Read-only window

90 days

Free after termination

Source escrow

Active

Notarised quarterly

What we export, in what time

ItemDeadline
Workspace metadata (users, roles, policies)Within 24h of request
Budgets & budget versionsWithin 24h of request
Transactions & journalWithin 48h of request
Reconciliation rules & runsWithin 48h of request
Forecasts (Pacer outputs)Within 72h of request
Audit ledger (Merkle log)Within 48h of request
Signed attestationsWithin 24h of request

If you choose to leave

  1. Notice of termination triggers an exit-readiness scan with named owner on both sides.
  2. Full export delivered within deadlines above; read-only access remains for 90 days.
  3. Sub-processors notified to delete in 30 days; deletion certificates archived in /trust-ledger.
  4. Final invoice reconciled to journal; outstanding credits paid out per /service-levels.

If we cease operations

  1. Source-code escrow (Iron Mountain, quarterly notarised deposits) released to customers.
  2. Continuity vendor on standby to run read-only mode for 12 months post-trigger.
  3. Open schemas on /standards mean competitors can import customer data without negotiation.
  4. Trustee-administered wind-down fund covers payout reconciliation and audit handover.