PHASE 1 COMPLETION:
TASK-005 — Live gitleaks scan:
Scanned 146 commits with gitleaks v8.20.1
Result: 1 finding — FALSE POSITIVE (model name llama-3.1-70b-versatile
in test fixture, not an API key)
Added to .gitleaksignore
rotation_log.md updated with scan results
VERDICT: No real secrets in git history — repo clean for extraction
TASK-006 — Legal templates (bilingual):
docs/legal/templates/IP_ASSIGNMENT_AGREEMENT.md — bilingual IP assignment
docs/legal/templates/PRIVACY_POLICY_EN.md — PDPL/GDPR-aware template
docs/legal/templates/PRIVACY_POLICY_AR.md — Arabic privacy policy
docs/legal/templates/TERMS_OF_SERVICE_EN.md — SaaS ToS with MENA pricing
docs/legal/templates/DPA_EN.md — Data Processing Agreement with annexes
All marked as "DRAFT — must be reviewed by Saudi counsel before use"
TASK-006 — Trademark Filing Kit:
docs/legal/templates/TRADEMARK_FILING_KIT.md
Covers: DEALIX (Latin) + ديلكس (Arabic) + logo
Classes 9, 42, 35 across KSA, UAE, Egypt, Jordan, Kuwait
Application text ready to paste into SAIP + equivalents
Agent recommendations (AGIP, Saba, Bird & Bird, Al Tamimi)
Budget: ~90-120K SAR for full MENA coverage
Founder Decision Package:
FOUNDER_DECISION_PACKAGE.md — single file with 4 decisions:
1. GitHub org name (recommend: dealix-io)
2. Entity structure (MISA vs DIFC vs ADGM)
3. Saudi counsel engagement (15-30K SAR)
4. Trademark filing (30-50K SAR initial)
Total founder time to unblock: ~1 week + ~50K SAR
PHASE 2 FOUNDATION:
DEALIX_PHASE2_BLUEPRINT.md — 18-month category leadership plan:
10 parallel streams (Frontend, Product, AI, Enterprise, Integrations,
Scale, Commercial, Customer Platform, Trust, Category POV)
Executable NOW vs Requires External Services vs Wait-for-PMF
Phase 2 completion criteria (NPS >=50, NRR >=120%, etc.)
TASK-F201 — Design System foundation (scaffolded):
packages/design-system/tokens/primitive.json — W3C Design Tokens format:
Brand palette (50-900), neutral (50-950), critical/warning/success/info
Space, radius, motion (duration + easing) tokens
Typography with Arabic fontFamily + arabic-adjustment (1.15) for size
Arabic line-height (1.8) for diacritics
packages/design-system/tokens/semantic.json — light + dark themes:
surface, fg, border, interactive, status semantic layers
packages/design-system/README.md — principles + integration guide
TASK-CAT1340 (prep) — @dealix/arabic-ui package (scaffolded):
packages/arabic-ui/src/normalize.ts:
Diacritic-insensitive search (fatha/kasra/damma stripped)
Hamza variants normalized (أ/إ/آ → ا)
Waw-hamza, ya-hamza, taa-marbuta, alef-maksura handled
arabicMatch() + arabicCompare() helpers
packages/arabic-ui/src/numerals.ts:
Western/Arabic-Indic/Eastern Arabic-Indic conversion
formatCurrency() for SAR/AED/EGP/USD/JOD/KWD
formatNumber() with locale awareness
packages/arabic-ui/src/direction.ts:
detectDirection() via Unicode bidi algorithm
isolate() using U+2068/U+2069 for mixed-direction content
isRTL() locale check
hasArabic() presence check
Future: release as OSS after 12 months of internal use
TASK-CAT1310 — Manifesto (bilingual draft):
marketing/manifesto.md — 4 principles in Arabic + English:
1. Arabic first, not Arabic translated
2. Decisions backed by evidence, not opinion
3. AI recommends, systems commit, humans approve
4. Saudi compliance built-in, not bolted on
Publication target: dealix.io/manifesto + dealix.io/بيان
TASK-CAT1320 — Dealix Labs (scaffolded):
docs/labs/README.md — research program structure:
Annual State of Arabic Enterprise AI report
Quarterly Arabic LLM Benchmarks
OTel semantic conventions proposal
Open source: @dealix/arabic-ui + @dealix/design-system
TRUTH.yaml updated:
Added Phase 2 capabilities section (all as 'partial' or 'roadmap')
Added ISO 27001/17/18 and bug bounty to security_claims (all false)
All gates GREEN:
Architecture Brief: 40/40
Release Readiness Matrix: 71/71 (up from 53/53)
Release Readiness Gate (blueprint): PASS
Truth Registry Validator: VALID
https://claude.ai/code/session_01W1rJthWDkasijTdXCfxVHs
4.9 KiB
Terms of Service — Dealix (Template)
DISCLAIMER: Template only. Must be reviewed by qualified Saudi counsel before publication. Version: 1.0 DRAFT Effective: [DATE]
1. Acceptance
By creating an account or using the Dealix platform ("Service"), you ("Customer") agree to these Terms. If you use the Service on behalf of an organization, you warrant that you have authority to bind that organization.
2. The Service
Dealix provides a Software-as-a-Service platform for enterprise revenue operations, including:
- Partner intake and dossier building
- Economics analysis
- Approval workflows with SLA tracking
- Evidence packs (SHA256 tamper-evident)
- Executive reporting and decision surfaces
3. Subscription and Fees
3.1 Tiers (current pricing in separate pricing sheet)
- Essentials: Mid-market
- Business: Large enterprise features
- Enterprise: Custom, dedicated infrastructure
3.2 Billing
- Monthly or annual billing in SAR, AED, or USD
- Prices exclude VAT (15% KSA, 5% UAE, 14% Egypt as applicable)
- Invoices ZATCA-compliant for KSA customers
- Payment due within 30 days of invoice
3.3 Renewals
- Annual subscriptions auto-renew unless cancelled 30 days before period end
- Pilot programs (90 days) convert to annual unless declined in writing
4. Customer Responsibilities
Customer agrees to:
- Provide accurate account information
- Keep credentials secure (MFA required for admin accounts)
- Obtain necessary consents from Data Subjects whose data is processed via the Service
- Not attempt to reverse engineer, decompile, or extract source code
- Not use the Service for unlawful purposes
- Comply with all applicable laws (PDPL, ZATCA, anti-money laundering)
5. Dealix Responsibilities
Dealix will:
- Provide the Service with reasonable skill and care
- Maintain 99.95% uptime SLA (Business+ tiers) — see SLA exhibit
- Keep customer data isolated per tenant (PostgreSQL RLS)
- Notify of material service changes with 30 days notice
- Maintain security controls per our published SECURITY.md
6. Data Ownership
- Customer Data belongs to the Customer
- Dealix receives limited license to process Customer Data solely to provide the Service
- Customer retains all rights to Customer Data and outputs
- Dealix owns all platform IP, features, and improvements
7. Confidentiality
Each party will protect the other's Confidential Information with reasonable care. Customer Data is confidential by default.
8. Acceptable Use
Prohibited activities:
- Sending spam or unsolicited marketing
- Using the Service to process data without lawful basis
- Testing security through unauthorized means (bug bounty program available)
- Circumventing trial/pilot limits
- Reselling the Service without written authorization
Violation may result in immediate suspension.
9. Warranties and Disclaimers
Dealix warrants that the Service will materially conform to its documentation.
EXCEPT AS EXPRESSLY STATED, THE SERVICE IS PROVIDED "AS IS" WITHOUT WARRANTIES OF ANY KIND. DEALIX DOES NOT WARRANT:
- AI output accuracy in all cases (see §10)
- Uninterrupted availability beyond SLA commitment
- Fitness for specific customer purposes not agreed in writing
10. AI-Generated Outputs
The Service uses large language models. Customer acknowledges:
- AI outputs are suggestions, not final decisions
- Human approval is required for all commercially sensitive actions (Class B in our policy framework)
- Customer remains responsible for decisions made based on AI outputs
- Dealix does not guarantee 100% accuracy of AI outputs
11. Limitation of Liability
EXCEPT FOR INDEMNIFICATION OBLIGATIONS, CONFIDENTIALITY BREACHES, OR INTENTIONAL MISCONDUCT:
- Aggregate liability is limited to 12 months of fees paid preceding the claim
- Neither party is liable for indirect, consequential, or lost-profits damages
12. Termination
Either party may terminate:
- For material breach with 30-day cure period
- For non-payment after 15-day notice
- Immediately for insolvency or illegal conduct
Upon termination:
- Customer may export data for 90 days post-termination
- Dealix deletes Customer Data within 90 days (subject to legal retention)
- Evidence packs remain accessible for audit purposes for 7 years
13. Governing Law and Disputes
- Governed by laws of the Kingdom of Saudi Arabia
- Disputes resolved by [SCCA arbitration in Riyadh / Saudi courts / agreed-upon forum]
- Language of proceedings: Arabic (with English translations)
14. Changes to Terms
Material changes announced with 30 days notice. Continued use after changes = acceptance.
15. Contact
Legal: legal@dealix.sa Support: support@dealix.sa Billing: billing@dealix.sa
Exhibits
- Exhibit A: Service Level Agreement (SLA)
- Exhibit B: Data Processing Agreement (DPA)
- Exhibit C: Acceptable Use Policy
- Exhibit D: Current Pricing
- Exhibit E: Subprocessors List