Business Associate Agreement

Knox Blockchain Secured — DealMatcherApp.com

This Business Associate Agreement ("Agreement") is entered into as of the date of last signature below, by and between the parties identified in Section 1.

1. Definitions

  1. "Business Associate" means Bonis Systems LLC, a Texas limited liability company, operating the DealMatcherApp.com platform, headquartered in San Antonio, TX. UEI: R2BPJDC5CBA3.
  2. "Covered Entity" means the organization or government agency executing this Agreement that engages Business Associate services for deal matching, procurement, or related AI-assisted operations.
  3. "Knox Blockchain" means the proprietary immutable audit ledger developed by Bonis Systems LLC, utilizing SHA-256 cryptographic hash chaining to create an append-only record of all system transactions, decisions, and data access events.
  4. "Protected Deal Information" (PDI) means any non-public deal data, procurement information, financial records, investor profiles, or government contract details processed through the DealMatcherApp.com platform.
  5. "Bruce AI" means the AI agent integrated into DealMatcherApp.com that performs automated deal matching, procurement analysis, and government data cross-referencing.
  6. "Platform" means DealMatcherApp.com and all associated APIs, databases, and services operated by Business Associate.

2. Obligations of Business Associate

Business Associate agrees to the following security and compliance obligations:

2.1 Encryption & Data Protection

2.2 Knox Blockchain Audit Trail

2.3 Access Controls

2.4 IP & Privacy Protection

3. Knox Blockchain Audit Guarantees

  1. Immutability: Once a block is written to the Knox ledger, it cannot be altered. Any tampering attempt breaks the SHA-256 hash chain and is immediately detectable.
  2. Completeness: Every system action that touches Protected Deal Information generates a Knox audit entry. No gaps in the audit trail.
  3. Availability: Knox audit data is available for export within 24 hours of a compliance review request.
  4. Integrity Verification: The entire Knox chain can be independently verified by recalculating SHA-256 hashes from genesis block forward.
  5. Non-Repudiation: Each Knox entry includes the authenticated actor ID, preventing denial of actions taken on the Platform.

4. Permitted Uses and Disclosures

Business Associate may use and disclose Protected Deal Information only for the following purposes:

  1. AI Deal Matching: Processing investor profiles against commercial listings using Bruce AI to generate match scores and recommendations.
  2. Procurement Optimization: Analyzing government contract opportunities via SAM.gov integration and matching qualified entities.
  3. Compliance Verification: Cross-referencing entities against SAM.gov, FinCEN, and other federal databases to verify eligibility and standing.
  4. Audit & Reporting: Generating compliance reports, audit exports, and analytics as required by Covered Entity or federal regulation.
  5. Platform Operations: Maintaining, securing, and improving the Platform infrastructure and AI models.

5. Breach Notification

In the event of a security incident involving Protected Deal Information, Business Associate shall:

  1. Notify Covered Entity within 72 hours of discovery
  2. Provide a Knox Blockchain audit export covering the incident timeframe
  3. Identify all affected records using Knox chain analysis
  4. Implement remediation measures and document them on the Knox ledger

6. Term and Termination

This Agreement shall remain in effect for the duration of the business relationship between the parties. Upon termination:

7. Signatures

Business Associate

Bonis Systems LLC

Signature

Printed Name

Title

Date

Covered Entity

_________________________

Signature

Printed Name

Title

Date

© 2026 Bonis Systems LLC. All rights reserved. This template is provided for business associate review and execution.

Document Version: 1.0 —