In December 2025 a company was locked out of its own website and email. Not by a hacker. By the person who founded it.
Lazarus Enterprises, an AI software business out of Boston, lost access to the registrar accounts for lazarusai.com and lazarus.enterprises after its founder revoked everyone else's administrative rights. The company took the matter to WIPO. Twice. It lost both times. Who actually owns those names is, as things stand, still unresolved.
Read quickly, this is a story about one messy founder dispute. Read properly, it is about something most companies are carrying right now and have never looked at.
Here is what sat underneath it. Before the company existed, the founder registered lazarus.enterprises himself, with his own money. After incorporation he registered lazarusai.com, again in his own name. The business grew, moved to Delaware, built a brand recognised in its market, and paid the renewals for years. From the outside, those looked like corporate assets. But on the registrar record, they belonged to one individual.
Nobody ever corrected that. There may have been a 2019 agreement meant to move the intellectual property across to the company. It was never cleanly executed, and when it mattered the company could not fully account for its own paperwork. So the record stood. Property follows registration. Equity can disagree all it likes.
This is the part worth sitting with, because it is not at all rare.
Every other asset in a company has an owner. Finance answers to a CFO. Legal holds the trademarks and the cap table. Bank accounts are held institutionally, with credentials tied to roles rather than to whoever opened them. The domain is the exception. It gets registered by whoever builds the first website, and after that everyone assumes. Marketing assumes IT owns it. IT assumes marketing chose it. Legal thinks the trademark covers it. Finance sees a small annual renewal and moves on. The one asset the entire business runs through is the one asset nobody is accountable for.
It stays invisible because it works. The site loads, the email sends, the brand grows. Nothing forces the question. Then a relationship sours, or an investor's due diligence opens the registrar record, or a founder walks out with the credentials, and the gap that cost nothing to ignore becomes the most expensive thing in the room.
When it breaks, the instinct is to reach for the process built for domain disputes. That is what Lazarus did, and it is worth understanding what that process is actually for. WIPO's procedure was designed in 1999 for a clean problem: someone registers a name belonging to a known brand, in bad faith, to sell it back or to pull away its traffic. Fast, no hearings, settled in weeks. For that, it works.
It was never built to decide who owns a name as between a company and its own founder. That question is contract, corporate authority, whether a document was signed and by whom. It needs discovery, witnesses, cross-examination. A panel that finishes in sixty days with none of those tools cannot answer it, and to its credit it did not pretend to. The founder had been the registrant from the beginning. Changing who can access an account is not the same as acquiring a domain, so there was no fresh bad faith to find. Both sides held a plausible claim. The panel left the ownership question exactly where it found it.
So the honest reading is not that WIPO failed. It is that the question should never have reached WIPO at all. It should have been closed at the start, in one line of one agreement, before there was anything to fight over. A board resolution. An assignment that names the domains directly instead of trusting a general IP clause to sweep them up. The cheapest moment to own a domain is the moment it is registered. Every moment after that, the price only climbs.
None of this needs a crisis to justify it. It needs someone whose job it is to know. Not the person who happened to set up the account years ago. Someone accountable for the names, the way finance is accountable for cash and legal is accountable for the marks.
The question was never whether domain names matter. Your company answered that the day it started routing everything it does through one. The quieter question is the one Lazarus never asked in time. Is anyone actually responsible for the names you are building the whole business on, or is everyone still assuming someone else is?
Grails has a free tool for the first step of answering that. The Domain Governance Generator produces a board-ready policy document setting out ownership, renewals, registrar security, and succession across your domains. It will not settle a dispute that has already started. It is built for the moment before there is anything to fight over.
With thanks to Vijayvikrant Nag, whose LiveLaw piece brought the case to my attention.