74. IP and Brand Protection
IP protection is not only about patents. For most startups, the urgent IP question is simpler: does the company clearly own the code, brand, content, data rights, designs, domain, and product assets it claims to own?
This is founder guidance, not legal advice. Use it to identify risks early and work with an IP lawyer where filings, assignment, licensing, or disputes matter.
The core IP question is: can the company prove it owns or has the right to use every asset it depends on?
For most startups, IP protection begins with boring proof. Who created the asset? Under what agreement? Was it assigned? Where is it stored? Who can access it? What license applies? Has the brand been checked? Can a future investor or acquirer verify the story without chasing five former freelancers?
The founder view of IP
Section titled “The founder view of IP”IP is not a trophy. It is business defensibility, trust, and clean ownership. A patent that does not matter to customers may be less important than a clean contractor assignment. A clever brand without a trademark search may become a rebrand. A beautiful codebase built by an agency may be dangerous if ownership is unclear.
Your first job is not to file everything. Your first job is to know what exists, who made it, who owns it, who can access it, and what would happen if that relationship ended tomorrow.
Types of startup IP
Section titled “Types of startup IP”Copyright
Section titled “Copyright”Software code, website copy, documentation, videos, designs, training material, product content, and creative assets may involve copyright. Founders often assume that if someone created something for the startup, the company owns it. Do not assume. Use proper assignment in founder, employee, contractor, agency, and vendor agreements.
Trademark
Section titled “Trademark”Your company name, product name, logo, tagline, and sometimes distinctive brand elements may need trademark thinking. Before falling in love with a name, search for conflicts, check domains and social handles, and speak to counsel about filing strategy. A forced rebrand after traction is painful because it affects SEO, trust, customer memory, investor materials, and legal documents.
Patent
Section titled “Patent”Patents may matter for deeptech, hardware, biotech, semiconductors, certain AI infrastructure, manufacturing, novel processes, and defensible technical inventions. They may matter less for ordinary SaaS workflow software. Patent decisions should be made with an IP professional because novelty, disclosure timing, prior art, jurisdiction, cost, and business value matter.
Trade secrets
Section titled “Trade secrets”Some knowledge is protected by secrecy rather than filing: algorithms, data cleaning methods, supplier terms, pricing models, fraud models, internal tools, customer lists, and playbooks. Trade secrets need process: limited access, confidentiality agreements, secure storage, logging, and employee awareness.
Domains and accounts
Section titled “Domains and accounts”Domains, hosting, GitHub, cloud, analytics, email, payment, design tools, app stores, ad accounts, social accounts, and API accounts are practical IP control points. If they sit in a founder’s personal account without shared recovery, the company has an operational risk.
Data is rarely “owned” in the simple way founders talk about it. You may have collection rights, usage rights, processing obligations, confidentiality obligations, deletion duties, customer restrictions, or privacy constraints. Treat data rights as a contract and compliance issue, not just a database asset.
IP audit by startup type
Section titled “IP audit by startup type”Audit source code, repositories, product designs, domain, documentation, customer data rights, open-source dependencies, integrations, and employee/contractor assignments. Enterprise customers may also ask about data processing, subprocessors, security, and whether any third-party code creates licensing exposure.
Marketplace
Section titled “Marketplace”Audit brand, domain, platform code, user-generated content terms, seller/buyer data rights, payment flow ownership, review content, dispute records, and supplier/vendor agreements. Marketplaces also need clear terms about who owns listings, photos, descriptions, and transaction data.
Consumer brand
Section titled “Consumer brand”Audit trademarks, social handles, app store names, domains, influencer/content rights, design assets, campaign content, music/image/video licenses, and user content permissions. Brand confusion is expensive after traction.
AI or data product
Section titled “AI or data product”Audit training data, customer data permissions, generated output terms, model provider terms, prompts, evaluation datasets, embeddings, source documents, and human review workflows. Do not assume that because data is accessible, it is usable for your product.
Agency-to-product transition
Section titled “Agency-to-product transition”If the company started as a service or agency, separate client-owned deliverables from reusable internal tools, templates, code libraries, datasets, and methods. Productizing agency work without checking old client contracts can create hidden restrictions.
IP hygiene
Section titled “IP hygiene”Assignment agreements
Section titled “Assignment agreements”Every founder should assign relevant pre-incorporation and ongoing work to the company. Employees should have IP and confidentiality terms. Contractors and agencies should assign deliverables and clarify whether they retain any background IP. If open-source or third-party assets are used, document them.
Contractor and agency contracts
Section titled “Contractor and agency contracts”For outsourced work, include scope, deliverables, acceptance, source files, repository access, credentials, IP assignment, confidentiality, open-source restrictions, payment, termination, and handover. Do not release final payment without receiving source files, documentation, credentials, and assignment.
Open-source review
Section titled “Open-source review”Open source is useful, but licenses matter. Track major libraries, license types, usage, and obligations. Be especially careful with copy-pasted code, AI-generated code that resembles licensed code, GPL-style obligations, and vendor code mixed into your proprietary product. For most startups, a lightweight dependency inventory is a good start.
Repository access
Section titled “Repository access”Use company-controlled repositories. Require two-factor authentication. Avoid founders and agencies using personal-only accounts for core infrastructure. Remove access when people leave. Maintain admin access with more than one trusted person. Protect production branches. Back up critical repos and deployment credentials.
Brand search and trademark filing
Section titled “Brand search and trademark filing”Before launch, do a basic search across trademark databases, company names, domains, app stores, social handles, and search engines. Before serious brand investment, get counsel to run a proper clearance and filing strategy. Filing early is often cheaper than rebranding late.
Documentation
Section titled “Documentation”Keep an IP folder with assignments, contractor agreements, agency contracts, trademark searches, filings, patent notes, open-source inventory, domain ownership, repository ownership, and important design/source files. Diligence becomes far easier when the story is documented.
The IP register
Section titled “The IP register”Maintain a living register with:
- Asset name.
- Type of asset.
- Creator.
- Current owner.
- Assignment proof.
- License or restrictions.
- Storage location.
- Access owner.
- Business importance.
- Risk level.
- Next action.
Start with code, domain, brand name, logo, website, product designs, key content, repositories, cloud accounts, datasets, model prompts, important documents, and agency deliverables.
IP Control Map
Section titled “IP Control Map”The IP register tells you what exists. The control map tells you who can change, transfer, delete, publish, or block it.
| Asset | Control risk to check |
|---|---|
| Domain and DNS | Is the registrant/company email correct? Who can change nameservers or transfer the domain? |
| Repository | Who has admin rights? Are protected branches, 2FA, and offboarding rules in place? |
| Cloud and deployment | Who can deploy, delete data, rotate secrets, change billing, or shut systems down? |
| Design/source files | Are Figma, Adobe, logo, font, and source files company-controlled? |
| App stores | Which account owns the app, certificates, payout details, and release authority? |
| Brand assets | Are logo, naming, content, videos, and campaign files stored with license proof? |
| Customer data | Who can export, delete, transform, or share it? What contracts restrict use? |
| AI workflows | Which prompts, datasets, evaluation files, and generated assets matter to the product? |
| Social and ad accounts | Who owns pages, pixels, audiences, handles, campaigns, and billing? |
Control risk is often more urgent than legal theory. If the company cannot access or prove control of an asset, the asset is fragile even if the founder believes ownership is obvious.
Pre-Fundraise IP Cleanup Sprint
Section titled “Pre-Fundraise IP Cleanup Sprint”Before a serious fundraise, run a two-week IP cleanup sprint.
| Day range | Work |
|---|---|
| Days 1-2 | List all core assets: code, domain, brand, product designs, datasets, content, docs, models, accounts. |
| Days 3-4 | Collect founder, employee, contractor, agency, and advisor IP assignment documents. |
| Days 5-6 | Check repository, cloud, domain, design, app store, analytics, and payment account ownership. |
| Days 7-8 | Build open-source and third-party asset inventory for material dependencies and assets. |
| Days 9-10 | Review customer/vendor contracts for IP transfer, work-for-hire, data rights, and reuse restrictions. |
| Days 11-12 | Review brand search, trademark status, domain/social handle risk, and filing strategy with counsel if needed. |
| Days 13-14 | Create an IP risk note: clean, open issues, owner, advisor, next action, and expected closure date. |
Investors do not need every early-stage startup to have a perfect patent portfolio. They do need confidence that the company owns what it says it owns and that the founders know where the risks are.
IP Triage: What To Fix First
Section titled “IP Triage: What To Fix First”Founders do not need to solve every IP issue at once. Triage by business risk.
Fix immediately
Section titled “Fix immediately”- Founder or agency code not assigned to the company.
- Domain, repository, cloud, app store, or payment account controlled only by a personal account.
- Brand name with obvious conflict or no basic search before launch.
- Contractor or employee creating core product without IP terms.
- Customer contract that transfers your platform, libraries, or reusable methods.
- Sensitive data used without rights, consent, or contractual permission.
Fix before fundraising or enterprise sales
Section titled “Fix before fundraising or enterprise sales”- Missing open-source inventory.
- No trademark filing strategy for a growing brand.
- No repository access policy.
- No documentation of AI tool usage for important code/content/data workflows.
- No clean folder of design/source files from agencies.
- No data rights analysis for AI, marketplace, fintech, health, education, or HR products.
Monitor
Section titled “Monitor”- Future patentability.
- International trademark expansion.
- Defensive publications.
- Competitor brand similarity.
- Employee side projects.
- Community/user-generated content rights.
The best IP system is not the one with the most filings. It is the one that protects the assets the company actually depends on.
Brand Naming Checklist
Section titled “Brand Naming Checklist”Before committing to a name:
- Search Google, app stores, domains, social handles, company names, and relevant trademark classes.
- Check whether the name is easy to spell, pronounce, and remember for your customer.
- Avoid names that are too close to competitors, large brands, regulated terms, or misleading claims.
- Check international meaning if you plan to sell globally.
- Check whether the domain strategy is acceptable even if the exact
.comis unavailable. - Ask counsel when the brand will matter commercially.
- File or reserve where appropriate before spending heavily on design, SEO, ads, or PR.
A name is not safe because a domain was available. Domain availability is only one signal.
AI, Data, And Generated Assets
Section titled “AI, Data, And Generated Assets”AI changes IP hygiene because founders now create code, text, images, analysis, prompts, datasets, and workflows through third-party tools.
Create a policy:
| Question | Founder decision |
|---|---|
| What tools are approved? | List tools for code, design, writing, support, sales, analytics. |
| What data is prohibited? | Customer confidential data, personal data, source code, credentials, unreleased financials, regulated data. |
| What output needs review? | Code, legal text, medical/financial claims, brand assets, customer-facing content. |
| Who owns prompts and workflows? | Store important prompts and evaluation workflows where the company can access them. |
| How are model/provider terms tracked? | Keep links to material vendor terms and enterprise agreements. |
Do not let confidential customer material leak into unapproved tools. Do not assume generated output is safe for important brand, legal, technical, or customer use without review.
Open-Source Policy
Section titled “Open-Source Policy”A lightweight policy is enough for most early startups:
- Track major dependencies and licenses.
- Avoid copy-pasting random code from blogs, forums, or AI output without review.
- Review GPL/AGPL-style obligations with technical/legal help before use in core products.
- Keep notices where required.
- Run dependency/security scans before enterprise diligence where possible.
- Make one engineer or founder responsible for dependency hygiene.
Open source is an advantage, not a problem. The problem is not knowing what you used.
Account Ownership And Offboarding
Section titled “Account Ownership And Offboarding”Practical control is part of IP protection.
Company-critical accounts include:
- Domain registrar.
- DNS.
- Email/admin workspace.
- GitHub/GitLab/Bitbucket.
- Cloud provider.
- Deployment platform.
- Analytics.
- Payment gateway.
- App stores.
- Design tools.
- Ad accounts.
- Social accounts.
- Customer support and CRM.
Rules:
- Use company email for company assets.
- Enable two-factor authentication.
- Keep at least two trusted admins.
- Store recovery information securely.
- Remove access when founders, employees, agencies, or contractors leave.
- Maintain a handover checklist for every external vendor.
Many IP crises are not lawsuits. They are access problems.
IP Assignment Workflow
Section titled “IP Assignment Workflow”Do not wait until fundraising to ask who owns the product. Create an assignment workflow before people create valuable work.
Use this rule: if someone creates company code, design, content, data structure, model, documentation, brand asset, customer workflow, or invention, the company should know the creator, the agreement, the assignment status, and where the asset lives.
Workflow:
- Before work starts, classify the person: founder, employee, contractor, agency, intern, advisor, consultant, open-source contributor, or customer co-creator.
- Use the right agreement before access is granted.
- Define deliverables, ownership, confidentiality, allowed portfolio use, open-source use, third-party assets, and handover format.
- Store signed documents in the company folder.
- Link the agreement to the asset in the IP register.
- On project completion or exit, collect source files, credentials, repositories, design files, documentation, model prompts, datasets, and deployment details.
- Remove access and record the handover.
The danger is not only that someone sues you. The danger is that an investor, acquirer, enterprise customer, or co-founder asks for proof and the company cannot produce it.
Agency And Freelancer Handover Checklist
Section titled “Agency And Freelancer Handover Checklist”Agencies and freelancers are useful, but founders must not outsource control.
Before final payment, collect:
- Source code and repository access.
- Design files, fonts, icons, images, and asset licenses.
- Deployment instructions and environment notes.
- Domain, DNS, hosting, analytics, email, and CMS/admin access where relevant.
- Third-party library list and license notes.
- Credentials transferred to company-controlled accounts.
- Documentation for custom integrations.
- Confirmation that customer data, test data, and credentials are deleted or returned where appropriate.
- Written confirmation of IP assignment if not already completed in the contract.
Payment should be tied to handover, not only screenshots or demo links. A working demo that the company cannot maintain is not a finished delivery.
Trademark Decision Tree
Section titled “Trademark Decision Tree”A brand name is not protected because you bought the domain. Use this sequence before investing heavily in a name:
| Step | Founder question |
|---|---|
| Search | Is the name already used by a similar product, company, or category? |
| Domain and handles | Can customers find you without confusion? |
| Trademark class | Which goods/services category matters for your business? |
| Similarity | Could a customer confuse your name, logo, sound, spelling, or category with another brand? |
| Geography | Are you India-only, global from day one, or likely to sell in the US/EU later? |
| Filing timing | Should you file before launch, before fundraising, before ads, or before category expansion? |
| Rebrand cost | What would it cost to change name after customers, SEO, invoices, app listings, and contracts exist? |
For founders, the practical answer is often: search early, ask a trademark professional before you scale the name, and file before the brand becomes painful to change.
Open-Source Release Gate
Section titled “Open-Source Release Gate”Open source is a strength, but unmanaged open source becomes diligence risk.
Before adding or releasing meaningful code, ask:
- What license applies?
- Is the license compatible with our product and distribution model?
- Are we modifying, distributing, embedding, or only using internally?
- Are there attribution, disclosure, source-availability, or notice obligations?
- Does any dependency create security or maintenance risk?
- Are we accidentally publishing proprietary code, credentials, customer data, internal URLs, or business logic?
- Who approves open-source release from the company?
Keep a dependency and release log. During enterprise review or acquisition, the company should be able to explain what it uses, why it is safe enough, and what obligations apply.
DPIIT and IPR support
Section titled “DPIIT and IPR support”Startup India’s DPIIT recognition page describes IPR support for eligible recognised startups, including patent fast-tracking and facilitator support subject to conditions. If IP protection matters to your company, check the current official Startup India and IP India pages and ask counsel whether the startup benefits apply.
IP Ownership Chain
Section titled “IP Ownership Chain”For every important asset, build an ownership chain. This is the clean story that connects creation, assignment, storage, access, and business use.
| Link in the chain | Question to answer | Evidence |
|---|---|---|
| Origin | Who created the asset and when? | Commit history, design file history, brief, invoice, email, task record. |
| Creator status | Was the creator a founder, employee, contractor, agency, advisor, intern, customer, or open-source contributor? | Agreement, offer letter, SOW, internship letter, contributor terms. |
| Assignment | Did the company receive ownership or the necessary license? | IP assignment, employment terms, contractor agreement, agency agreement, license. |
| Third-party inputs | Were stock assets, fonts, datasets, libraries, AI tools, customer material, or open-source code used? | License records, dependency list, vendor terms, attribution notes. |
| Company control | Does the company control the repository, source file, account, domain, model, dataset, or brand asset? | Admin list, account owner, folder link, recovery details, offboarding record. |
| Restrictions | Are there limits on reuse, geography, field, customer segment, publicity, confidentiality, or transfer? | Contract clause, DPA, customer agreement, license term, legal note. |
| Business criticality | Would losing or challenging this asset materially hurt the company? | Risk rating, customer dependency, revenue dependency, product dependency. |
| Next action | What must be fixed, filed, assigned, searched, documented, or reviewed? | Owner, due date, advisor, status. |
This chain is especially important for assets created before incorporation, built by agencies, copied from old client work, generated with AI tools, trained on customer data, or stored in a founder’s personal account.
If the chain breaks, fix the break closest to the business risk. For example, if the domain is in a founder’s account, move control. If the agency never assigned code, get assignment and source files. If the brand was never searched, run clearance before spending heavily. If AI workflows touch customer data, review rights and confidentiality before scaling the workflow.
IP Chain Of Custody Review
Section titled “IP Chain Of Custody Review”IP problems often appear late: during fundraising, enterprise diligence, acquisition, founder exit, agency dispute, or open-source review. Run a chain-of-custody review before those moments.
| Asset | Who created it? | When? | Under what agreement? | Company control evidence | Risk |
|---|---|---|---|---|---|
| Source code | Founder/employee/contractor/agency agreement | Repo ownership, commit history, assignment | Low/medium/high | ||
| Brand name/logo | Designer/agency/founder agreement | Design files, invoices, assignment, search notes | Low/medium/high | ||
| Domain/social handles | Purchased by whom? | Company account, access recovery, renewal owner | Low/medium/high | ||
| Content/data | License, customer, public, generated, internal | Usage rights, consent, source notes | Low/medium/high | ||
| AI-generated assets | Tool terms and human review | Prompt/source notes, review, usage policy | Low/medium/high | ||
| Customer-specific work | Contract terms | Ownership and reuse rights | Low/medium/high |
Use this escalation rule:
| Finding | Action |
|---|---|
| Created by founder before incorporation | Document assignment to company with counsel. |
| Created by agency/freelancer without clear IP terms | Get assignment or replacement plan before scaling reliance. |
| Key account controlled by personal email | Move to company-controlled access and recovery. |
| Open-source or third-party component with unclear license | Review before enterprise sale, distribution, or public release. |
| Customer-funded custom work | Confirm what the company can reuse in the product. |
The founder’s goal is not to own every possible thing in the abstract. The goal is to make the company able to use, sell, modify, protect, and transfer its core assets without surprises.
Brand And IP Diligence Pack
Section titled “Brand And IP Diligence Pack”Before fundraising, enterprise sales, a major partnership, or acquisition conversations, prepare a brand and IP diligence pack. The pack should let a serious outsider understand what the company owns, what it uses under license, what is still uncertain, and what is being fixed.
Include:
| Pack item | What it proves |
|---|---|
| IP register | The company knows its core assets, creators, owners, assignment status, restrictions, and risk level. |
| Founder and contractor assignments | Core product, design, content, data structures, and pre-incorporation work were transferred or licensed properly. |
| Repository and account control map | Code, cloud, domain, app stores, analytics, payment, and design assets are company-controlled. |
| Brand search notes | The name, logo, domain, social handles, and category were checked before heavy investment. |
| Trademark and filing status | The company knows what has been filed, where, by whom, and what remains open. |
| Open-source inventory | Material dependencies and license questions are visible. |
| Third-party asset licenses | Fonts, icons, images, video, music, templates, datasets, and vendor assets have usage proof. |
| Customer and agency contract notes | Custom work, client-funded builds, and reusable product rights are understood. |
| AI/data usage note | Important AI-generated or data-derived assets have source, review, and rights notes. |
| Open risk memo | Unresolved issues have owner, advisor, next action, and target date. |
The pack should be honest. Do not hide unresolved issues from yourself. A clean diligence story is not “there are no risks”; it is “we know the risks, here is the evidence, here is what is fixed, and here is what remains open.”
Review this pack before:
- Raising money.
- Signing a strategic customer or partner.
- Spending heavily on brand marketing.
- Hiring agencies or freelancers for core product work.
- Launching in a new country.
- Publishing technical research, model details, or potentially patentable material.
- Allowing a founder, agency, or senior employee to exit.
Brand Decision Gate
Section titled “Brand Decision Gate”Before investing heavily in a name, logo, domain, campaign, or product line, run a brand decision gate. A good name is not only memorable. It must be usable, ownable enough for your stage, and unlikely to create avoidable conflict.
| Gate | Question |
|---|---|
| Search | Have we searched obvious company, product, domain, app store, social, and trademark conflicts? |
| Category | Are we using the name in a category where similar marks already exist? |
| Geography | Are we India-only, global-from-India, or planning foreign markets? |
| Domain/social | Do we control the important domains, handles, and recovery access? |
| Customer clarity | Can customers spell, remember, and distinguish it? |
| Legal review | Has counsel reviewed the risk before major spend, filing, or launch? |
| Filing plan | What should be filed now, what can wait, and who owns the process? |
| Rebrand cost | If forced to change later, how painful would it be? |
Use this decision rule:
| Risk level | Action |
|---|---|
| Low | Proceed, document search notes, and set a filing/review date. |
| Medium | Get counsel review before major marketing or fundraising use. |
| High | Rename or narrow use unless there is a strong strategic reason and legal advice. |
Do this early. Rebranding before launch is annoying. Rebranding after customers, investors, app listings, SEO, contracts, invoices, and press is expensive.
IP Ownership Review By Event
Section titled “IP Ownership Review By Event”Do not review IP only once. Review it when the business changes.
| Event | What to check |
|---|---|
| Before incorporation | Founder-created code, domain, brand, designs, data, content, and assets. |
| Before hiring/contractors | Employment, contractor, agency, confidentiality, assignment, and access terms. |
| Before enterprise sales | Repository control, open-source inventory, security/data promises, customer-specific rights. |
| Before fundraising | IP register, assignments, brand notes, open risk memo, data room evidence. |
| Before publishing technical content | Patent/disclosure timing, confidentiality, customer data, third-party assets. |
| Before founder/employee exit | Access removal, assignment confirmation, device return, confidentiality, knowledge transfer. |
| Before acquisition talks | Full diligence pack, unresolved risk list, advisor review, asset transfer restrictions. |
This event-based review is more useful than a static checklist because startup IP risk changes with customers, hires, code, brand, data, and fundraising.
Common mistakes
Section titled “Common mistakes”Founder code not assigned
Section titled “Founder code not assigned”If a founder wrote the first product before incorporation, the company may still need written assignment. Clean this early.
Agency owns the code or design
Section titled “Agency owns the code or design”Many founders pay an agency and assume ownership transferred. The contract decides. Get assignment, source files, credentials, and handover.
Trademark conflict
Section titled “Trademark conflict”A name can feel available because the domain was available. That is not enough. Trademark conflicts can force a costly rebrand.
Open-source license violations
Section titled “Open-source license violations”License issues can appear during enterprise security review, fundraising diligence, or acquisition. Track dependencies before it becomes detective work.
No brand protection
Section titled “No brand protection”If customers remember your name, competitors can notice it too. Protect the brand before it becomes valuable enough to fight over.
No repository control
Section titled “No repository control”If one founder, freelancer, or agency controls the repository, cloud, domain, or deployment account, the company is fragile. Fix access before conflict, illness, or departure.
Publishing before filing strategy
Section titled “Publishing before filing strategy”For some inventions, public disclosure can affect patent strategy. Do not publish papers, demos, pitch materials, or technical blogs about a potentially patentable invention without checking timing with counsel.
Ignoring design and content rights
Section titled “Ignoring design and content rights”Images, icons, fonts, music, videos, templates, stock assets, and freelancer-created content can carry licenses. Marketing assets are IP too.
Assuming AI output is automatically safe
Section titled “Assuming AI output is automatically safe”AI-generated code, text, images, or designs may create originality, license, confidentiality, or brand-risk questions. Use review processes for important assets and avoid feeding confidential or restricted material into tools without approval.
IP Chain Of Title Register
Section titled “IP Chain Of Title Register”Investors and acquirers will eventually ask a simple question: does the company actually own what it sells? The answer should not depend on founder memory.
Maintain a chain-of-title register:
| Asset | Creator | Agreement proving ownership | Repository/location | Risk |
|---|---|---|---|---|
| Source code | Founder/employee/contractor/agency | Employment, contractor, or assignment agreement | ||
| Brand name/logo | Founder/designer/agency | Design agreement and assignment | ||
| Website/content | Founder/marketer/freelancer/AI-assisted | Contract, license, content policy | ||
| Data/processes | Company/customer/vendor/public source | Terms, consent, license, contract | ||
| Product designs | Designer/agency/product team | Assignment and source files | ||
| AI outputs/prompts | Employee/vendor/tool | Tool terms and internal policy |
If an asset matters to customers, revenue, fundraising, or acquisition, ownership evidence should exist.
Open Source And AI Asset Review
Section titled “Open Source And AI Asset Review”Modern products are built with open-source packages, design kits, datasets, AI tools, generated text, generated images, code assistants, and third-party APIs. That is normal. The founder’s job is to know where risk lives.
Review:
| Asset type | Founder question |
|---|---|
| Open-source code | Are licenses compatible with commercial use and distribution? |
| AI-generated code | Does an engineer understand and own it? |
| AI-generated content/images | Are usage rights, brand risk, and originality reviewed? |
| Datasets | Do we have rights to collect, store, process, and commercialize? |
| Design assets | Are icons, fonts, templates, and images licensed properly? |
| Customer data | Does the contract allow the intended use? |
Do not turn this into legal panic. Turn it into an asset review habit.
Brand Protection Watchlist
Section titled “Brand Protection Watchlist”A startup brand needs basic protection before it becomes visible.
Watch:
- Domain ownership and renewal.
- Social handles and app store names.
- Trademark search and filing where appropriate.
- Similar names in the same category.
- Founder, agency, or employee ownership of brand assets.
- Logo/source file ownership.
- Misleading use of customer logos or partner names.
Brand work is not only design. It is trust, searchability, legal safety, and future acquisition hygiene.
IP Diligence Readiness Review
Section titled “IP Diligence Readiness Review”Before fundraising, enterprise sales, partnership, or acquisition conversations, run an IP diligence readiness review. The review should answer one question: can the company prove it owns and can use the assets it depends on?
| Area | Evidence to check |
|---|---|
| Founder-created work | Assignment into company, pre-incorporation transfer if applicable. |
| Employee work | Employment agreements, IP assignment, confidentiality, access logs. |
| Contractor/agency work | Work order, assignment, source files, credentials, handover proof. |
| Open-source software | Dependency list, license review, attribution and distribution obligations. |
| AI-generated assets | Tool terms, input data rules, human review, originality/brand review. |
| Brand | Name search, domain ownership, trademark filing/search where appropriate, logo/source ownership. |
| Customer data | Contract rights, consent basis, data map, retention/deletion process. |
| Repositories/cloud/accounts | Company-controlled admin access, backup owner, offboarding process. |
Classify each item:
| Status | Meaning |
|---|---|
| Green | Evidence exists and ownership/use rights are clear. |
| Yellow | Likely okay but evidence is incomplete or scattered. |
| Red | Ownership/use rights are unclear, disputed, personal, or missing. |
Fix red items before they enter diligence. Fix yellow items before they become urgent. IP cleanup is far easier while relationships with founders, contractors, designers, and agencies are still warm.
Brand And IP Source Verification
Section titled “Brand And IP Source Verification”Founders often confuse “available online” with “safe to use.” This is risky for names, logos, code, images, datasets, fonts, templates, and AI outputs.
Use this source verification rule:
| Asset | Verify |
|---|---|
| Company name | Domain, social handles, app store names, trademark search, category confusion. |
| Logo/design | Designer/agency assignment, source files, font/icon/image licenses. |
| Code | Repository ownership, employee/contractor assignment, open-source licenses. |
| Dataset | Collection rights, customer terms, consent, privacy, third-party licenses. |
| Content | Author/source, stock licenses, AI policy, customer/logo permission. |
| Technical invention | Publication timing, patentability questions, founder disclosure habits. |
When in doubt, document the source and ask the right advisor early. A clean source trail is cheaper than a rebrand, takedown, diligence delay, or customer trust issue.
Repository And Credential Control Drill
Section titled “Repository And Credential Control Drill”Many IP problems are not courtroom problems. They are access problems. A founder leaves, an agency keeps the GitHub repository, the domain is in a personal account, the production cloud has one admin, or a freelancer owns the design source files.
Run a control drill every quarter:
| Asset | Control question |
|---|---|
| Code repository | Is it under a company-controlled organization with at least two trusted admins? |
| Cloud account | Does the company control billing, root/admin access, MFA, and recovery? |
| Domain and DNS | Is the domain registered to the company or founder-authorized account with renewal protected? |
| Design files | Are source files in a company workspace, not only a designer’s personal account? |
| App stores and social accounts | Are ownership, recovery email, and MFA controlled? |
| Production secrets | Are keys stored securely with rotation and offboarding process? |
| AI/tool accounts | Are important prompts, outputs, datasets, and credentials not trapped in personal accounts? |
| Agency/freelancer handover | Are source files, credentials, licenses, and assignments delivered before final payment? |
Access loss scenario
Section titled “Access loss scenario”Ask:
If one founder, engineer, agency, or freelancer disappears tomorrow, can the company still ship, deploy, bill, renew domains, recover accounts, prove ownership, and serve customers?If the answer is no, treat it as an operating risk, not only an IP risk. The fastest cleanup is usually simple: move assets into company-controlled accounts, add backup admins, document ownership, and close contractor handovers properly.
AI, Data, And Content Provenance Review
Section titled “AI, Data, And Content Provenance Review”Modern startups often build with AI tools, scraped data, purchased datasets, customer uploads, public content, templates, open-source code, and freelancer-created assets. This can create hidden IP and data risk if nobody tracks provenance.
For each important asset, record:
| Asset type | Provenance questions |
|---|---|
| AI-generated text/design/code | Which tool was used, what inputs were used, who reviewed output, and can it be used commercially? |
| Customer data | What contract, consent, or product term allows use, retention, analysis, or model improvement? |
| Public web data | Was collection allowed by law, terms, robots/access rules, and privacy expectations? |
| Third-party dataset | What licence, renewal, redistribution, attribution, and audit obligations exist? |
| Open-source code | What licence applies, and does distribution, modification, or SaaS use create obligations? |
| Stock images/icons/fonts/templates | Is the licence valid for product, marketing, resale, or client work? |
| Freelancer/agency output | Is there assignment, source delivery, licence proof, and payment proof? |
Use a provenance register:
| Asset | Source | Licence/permission | Restrictions | Owner | Proof link | Risk |
|---|---|---|---|---|---|---|
This is especially important for AI products, data products, media/content businesses, developer tools, fintech, healthtech, HRtech, and education products. The founder does not need to over-lawyer every asset, but the company should know where important inputs came from and what rights it has.
Reader action
Section titled “Reader action”Create an IP register with these columns: asset, creator, current owner, proof of assignment, location, access owner, risk, next action, and advisor. Start with code, domain, brand name, logo, website, product designs, customer data, key content, repositories, cloud accounts, and agency deliverables.
Official references
Section titled “Official references”- Intellectual Property India
- Companies Act, 2013 on India Code
- Startup India DPIIT Recognition and Benefits