A usable software handback includes the source and every account, artifact, configuration record, and operating document the buyer needs to rebuild, deploy, observe, and maintain the system.
Inventory the technical chain from source to service
List every source repository, branch and release convention, package registry, build service, container registry, cloud project, deployment target, database, object store, queue, domain, DNS zone, certificate, identity provider, payment account, email service, analytics property, monitoring system, and error tracker used by the delivered application. Record the buyer-controlled owner and the access role required for each.
The handback should include environment-variable names and provisioning sources without placing secret values in the inventory. Temporary credentials, personal accounts, or a builder-owned domain need a transfer or replacement plan. The technical review can verify account control and configuration paths, while legal ownership of contracts, licenses, or intellectual property belongs with the buyer's advisers.
Include product and operating artifacts
Collect approved designs, original editable files, fonts and asset licenses, content sources, API specifications, schemas, data dictionaries, migrations, seed fixtures, test data, backups, runbooks, architecture and decision records, known defects, release notes, support procedures, vendor contacts, and outstanding renewals. Export formats should remain usable without the builder's personal subscription where possible.
CISA's software supply-chain guidance describes source review, testing, third-party verification, and process evidence as acquisition controls. Those controls depend on the buyer possessing the artifacts needed to inspect and operate the delivery, which is why a live URL and repository access alone do not complete the handback.
Verify transfer instead of checking boxes
For each material asset, confirm that an authorized buyer account can access it, that recovery and billing ownership are correct, and that the asset appears in the clean build or operating path where expected. Record missing access, pending transfers, personal-account dependencies, renewal dates, and the evidence needed to close each item. For every vendor service, record the account owner, billing owner, renewal date, export path, and recovery contact, so the inventory shows whether the buyer can administer the service without continued access from the delivering party.
Handback Review prepares the technical inventory through Reality Contact, LLC. The buyer and the buyer's advisers decide whether the transfer satisfies contractual and ownership requirements.
Where the service stops
Reality Contact, LLC performs technical verification and document preparation, but does not interpret contract rights as legal advice, determine payment entitlement, certify security, conduct penetration testing, contact the delivering party, or make the buyer's acceptance decision. The buyer reviews the evidence with any advisers needed and chooses whether to accept the delivery, require repairs, or withhold acceptance or payment where the contract permits. This is technical verification and document preparation; it does not replace legal, security, procurement, intellectual-property, or contractual review. We do not promise that the software is defect-free, that every requirement is testable, or that any technical finding determines payment or acceptance rights.
Sources: CISA guidance on software supply-chain verification and acquisition controls; NIST Guide to Software Acceptance.