Raxx · internal docs

internal · gated ↑ index

ESIGN + UETA compliance checklist — Raxx NDA portal

ATTORNEY REVIEW REQUIRED BEFORE USE. This is a research-grade implementation checklist produced by a non-lawyer, intended as a starting-point for a contract attorney (SaaS / technology-transactions background) and software-architect to collaboratively validate before building. The items below track primary-source statutory text (ESIGN Act, UETA model text) but are NOT a compliance opinion. A signed NDA is only as enforceable as its implementation — the attorney should review this checklist alongside nda-template.md as one deliverable.

Status: research-only. Last updated: 2026-04-22. Audience: software-architect (epic #161 phase 3 portal design) + attorney consult (#151).


How to use this document


Statutory hook

Portal implementation

Attorney-to-confirm


2. Intent to sign — [MUST]

Statutory hook

Portal implementation

Attorney-to-confirm


3. Attribution — [MUST]

Statutory hook

Portal implementation

For every signature event, portal must capture and store:

Attorney-to-confirm


4. Record retention — [MUST]

Statutory hook

Portal implementation

Attorney-to-confirm


5. Ability to retrieve / download — [MUST]

Statutory hook

Portal implementation


Statutory hook

Critical interpretation

Consent withdrawal applies to future records only. The NDA itself, once signed, is a binding contract; the signer cannot unilaterally "withdraw" their signed NDA. The portal and the NDA language (§10.5) must make this distinction crystal-clear to avoid signer confusion.

Portal implementation

Attorney-to-confirm


7. Tamper-evidence — [MUST]

Statutory hook

Portal implementation

Attorney-to-confirm


8. UETA state-specific variations — [CONSIDER]

Status as of 2026-04-22

Portal implementation

Data to log per signer


9. Accessibility — [SHOULD]

Rationale

ESIGN / UETA do not directly mandate accessibility, but a signer who can't meaningfully read the consent disclosures or the NDA arguably did not give informed consent. For federally-funded contexts there are additional obligations (not Raxx's).

Portal implementation


10. Privacy — scoped data minimization — [MUST]

Not ESIGN/UETA directly, but epic #161 invariant

Portal implementation

Attorney-to-confirm


11. Admin surface — [SHOULD]

Not strictly an ESIGN requirement, but operationally necessary

Portal implementation (ties into console.raxx.app epic #146)


12. Pre-launch readiness gate — [MUST]

Before the portal goes live:


13. Out of scope for this doc


14. References to other docs


Sources (primary + explainer)

See nda-framework.md §11 for the full citation list. Key items for this checklist:


ATTORNEY REVIEW REQUIRED BEFORE USE. Review this checklist with the contract attorney (SaaS / technology-transactions background) alongside nda-template.md at the #151 consult. The checklist is an input to software-architect's phase-3 portal design, not a substitute for attorney-blessed compliance review.