For consultants, dev shops, forward-deployed engineers & everyone who pitches with demos

Your best pitch is a working demo. Protect it.

A screenshot of your prototype is all AI needs to rebuild it overnight. POCX puts a gate on your demo — every viewer proves who they are and signs your terms before they see a single screen.

Free for 3 invited viewers per demo · or self-host free forever · no card required

ConsultanciesDev shopsForward-deployed engineersAgenciesFreelancersFounders

demo.acme.dev

ACME PTE LTD · PRIVATE DEMO

Project Falcon

you@company.com
Email me a code

Protected by POCX — access is logged and terms-gated

The new reality

Building used to be the moat. Now it’s the easy part.

For years a demo was safe to show — rebuilding it was too much work to bother. That changed overnight.

01

You pitch a prospect with your demo.

02

They screenshot it and paste it into Claude, Codex or Cursor: “build me this.”

03

By morning they have a working copy — and never needed you.

Your ideas are worth more than ever — and easier to take than ever. The demo is the pitch. You can’t win the deal without showing it.

What POCX does

Show the work. Keep the idea.

POCX doesn’t hide your demo — it makes seeing it accountable. Think of it as a digital NDA that enforces itself: before anyone reaches a single screen of your prototype or proof of concept, they prove who they are and e-sign your Terms of Access. A screenshot is no longer anonymous — it’s tied to a named person who agreed, in writing, not to build on your work without you.

How it works

From unprotected to protected in three steps.

01 — Create

Register your demo

Name it, name the company that built it, invite your viewers by email. Terms, branding and session rules — all customizable from the dashboard.

02 — Drop in

Drop in the gate

One file, three env vars — or hand this whole step to your coding agent. The SDK is a single TypeScript file with zero dependencies:

proxy.ts
# curl -o lib/pocx.ts https://pocx.dev/sdk/pocx.ts

import { createPocxGate } from "./lib/pocx";
const gate = createPocxGate();
export const proxy = gate.nextProxy();

03 — Send the link

Send the link

Viewers sign in with their invited email, e-sign your Terms of Access, and land in your demo. You watch sessions and signatures live — and can revoke anyone, instantly.

Agent-first

Vibe-coding your prototype? Then you already know how to install POCX.

POCX ships llms.txt and a single-file, zero-dependency SDK, built so a coding agent can do the entire integration. Create your gate in the dashboard, then paste one prompt — your agent downloads the SDK, wires the middleware and asks you for the three keys from your PoC's Overview tab.

paste into your agent

Add POCX protection to this app. Follow the instructions at https://pocx.dev/llms.txt exactly.

That's genuinely it — one file, three env vars, nothing added to package.json. (Prefer doing it by hand? It's four lines — see the docs.)

Works withClaude CodeCodexCursorWindsurfany agent that can read a URL

See it in action

The next $100M idea is behind this gate.

Acme Pte Ltd won't show Project Falcon to anyone without a signature. Go through the gate exactly as your clients would: enter any email you own, get a real one-time code, e-sign real Terms of Access — a signed PDF certificate lands in your inbox — and see what all the secrecy is about.

A real gate protecting a fictional idea. Any email works — it's only used for this demo's access flow, and you can sign out from inside.

Features

The whole front door, handled.

Identity, terms, sessions, evidence. POCX decides who gets into your demo, prototype or proof of concept (PoC) — and on what conditions. Your app stays exactly as you built it.

Invite-only + email codes

Only invited emails get in. Codes are hashed, single-use, rate-limited, and lock out after five attempts. No passwords — ever.

Terms of Access, e-signed

Viewers sign by typing their full name. Every signature records that name, a SHA-256 hash of the exact text, timestamp, IP and user agent — plus a signed PDF certificate emailed to the signer.

Session control

TTL and idle timeouts, one-click revoke for any viewer, and a panic button that revokes every session at once.

Audit trail (Pro)

Every code request, denial, login, signature and revocation — plus in-app access events from the SDK. Export it all as CSV.

Branded hosted gate

Your company name, your demo’s name, your brand color. The gate looks like yours because it is — we just run it for you.

Built for coding agents

POCX ships llms.txt and a single-file SDK, so Claude Code, Codex or Cursor can integrate the whole thing end-to-end.

Why it holds up

A login wall is not protection. A signature is.

Your demo embodies your thinking — the designs, the workflows, the idea your prospect is evaluating. A password keeps strangers out. It does nothing when the people you invited take what they saw and build it without you.

POCX’s standard Terms of Access work like an NDA — but signed at the door instead of filed in a drawer, and with the clause NDAs forget: if you build on this work, you engage us. Every viewer e-signs it before they see a single screen — and every signature is recorded with the SHA-256 hash of the exact text they agreed to, their verified email, IP, and timestamp, sealed in a PDF certificate.

That turns reuse-without-engagement from a grey area into a signed, enforceable commitment — with the evidence trail to back it up.

Signature certificate

RECORDED
Signature idsig_9f2ce41ab7
Signed byJane Tan · jane@client.com
Terms versionv1.2
Timestamp2026-07-07 09:14:32 UTC
IP address203.0.113.42
SHA-256e3b0c44298fc1c149afbf4c8996fb924…

PDF certificate emailed to the signer automatically.

From the field

Built for people who ship demos for a living.

I figured wiring up access control would eat my whole afternoon. Instead I handed Claude the llms.txt link and it just did it — the gate was live before I’d finished my coffee.

Forward-deployed engineer

client PoCs on Vercel

There was no way I was spinning up servers for a throwaway prototype, so the hosted version was an easy yes. Now nothing reaches a client until it’s sitting behind the gate.

Independent product consultant

prototype-led sales

Open source

Don’t want to pay? Run it yourself.

POCX is fully open source — like n8n or Supabase. Not a stripped-down “community edition”: the entire product — the gate, the dashboard, the audit trail, the ops console — all of it. Self-host and every feature is free, forever.

The cloud at pocx.dev is for people who’d rather not run infrastructure. You pay for the convenience of not hosting it, not for the software. Either way, your ideas are protected.

AGPL-3.0 · your data, your server, your rules.

~/your-project
git clone https://github.com/saadkamal/pocx
# every feature. no seat limits. your server.
open sourceAGPL-3.0self-host free

Pricing

Start free. Stay protected.

See pricing

Free

US$0 forever

  • Up to 3 viewer seats per demo
  • Email-code gate + e-signed terms with PDF
  • Session control & instant revoke
Start free
MOST PROTECTIVE

Pro

US$39 /workspace/month

US$39/mo · or US$320/yr (save 32%)

  • Unlimited viewer seats
  • Full audit trail with CSV export
  • Priority support
Start free

Or run the open-source version yourself — free, forever. GitHub

Ship the demo. Keep the idea.

Free on the cloud for three viewers per demo, or self-host the whole thing for free. Your ideas, protected either way.